[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1455 --- ntp sntp

ID: oval:org.secpod.oval:def:1700366Date: (C)2020-07-22   (M)2024-01-29
Class: PATCHFamily: unix




ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim"s ntpd instance. ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp

Platform:
Amazon Linux 2
Product:
ntp
sntp
Reference:
ALAS2-2020-1455
CVE-2020-11868
CVE-2020-13817
CVE    2
CVE-2020-13817
CVE-2020-11868

© SecPod Technologies