Lucene search

K
f5F5F5:K43205719
HistoryMay 25, 2016 - 12:00 a.m.

K43205719 : NTP input validation vulnerability CVE-2016-1550

2016-05-2500:00:00
my.f5.com
15

AI Score

6.2

Confidence

High

EPSS

0.005

Percentile

76.3%

Security Advisory Description

An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92. An attacker can send a series of crafted messages to attempt to recover the message digest key. (CVE-2016-1550)
Impact
This vulnerability may allow an attacker to conduct a timing attack and compute the value of the valid authentication digest, causing forged packets to be accepted by ntpd.