Wind River Support Network

HomeDefectsLIN7-5562
Fixed

LIN7-5562 : Security Advisory - ntp - CVE-2015-7979

Created: Jan 27, 2016    Updated: Sep 8, 2018
Resolved Date: Mar 25, 2016
Previous ID: SCP7-293
Found In Version: 7.0.0.12
Fix Version: 7.0.0.14
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

It was found that when NTP is configured in broadcast mode, an off-path attacker could broadcast packets with bad authentication (wrong key, mismatched key, incorrect MAC, etc) to all clients. The clients, upon receiving the malformed packets, would break the association with the broadcast server. This could cause the time on affected clients to become out of sync over a longer period of time.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-7979  

Other Downloads


CVEs


Live chat
Online