CVE-2016-1548

NameCVE-2016-1548
DescriptionAn attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time after the mode has been changed. ntpq gives no indication that the mode has been switched.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-559-1, DSA-3629-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ntp (PTS)jessie, jessie (lts)1:4.2.6.p5+dfsg-7+deb8u3fixed
stretch1:4.2.8p10+dfsg-3+deb9u2fixed
buster1:4.2.8p12+dfsg-4fixed
bullseye1:4.2.8p15+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ntpsourcewheezy1:4.2.6.p5+dfsg-2+deb7u7DLA-559-1
ntpsourcejessie1:4.2.6.p5+dfsg-7+deb8u2DSA-3629-1
ntpsource(unstable)1:4.2.8p7+dfsg-1

Notes

http://support.ntp.org/bin/view/Main/SecurityNotice#April_2016_NTP_4_2_8p7_Security

Search for package or bug name: Reporting problems