Wind River Support Network

HomeDefectsLIN7-4997
Fixed

LIN7-4997 : Security Advisory - ntp - CVE-2015-7705

Created: Oct 22, 2015    Updated: Sep 8, 2018
Resolved Date: Nov 25, 2015
Previous ID: LIN4-33112
Found In Version: 7.0.0.9
Fix Version: 7.0.0.12
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

A flaw was found in the way NTP handled rate limiting. An attacker able to send a large number of crafted requests to an NTP server could trigger the rate limiting on that server, and prevent clients from getting a usable reply from the server.

The default NTP configuration in Red Hat Enterprise Linux does not enable rate limiting.

External References:

https://www.cs.bu.edu/~goldbe/NTPattack.html

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7705

Other Downloads


CVEs


Live chat
Online