Lucene search

K
f5F5F5:K20804323
HistoryMay 25, 2016 - 12:00 a.m.

K20804323 : NTP vulnerability CVE-2016-2518

2016-05-2500:00:00
my.f5.com
20

6.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.9%

Security Advisory Description

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value. (CVE-2016-2518)
Using a crafted packet to create a peer association with hmode > 7 causes the MATCH_ASSOC() lookup to make an out-of-bounds reference.
Impact
A remote attacker may be able to cause a denial of service (DoS) using a crafted packet.