Oval Definition:oval:com.ubuntu.xenial:def:20151853000
Revision Date:2015-04-07Version:1
Title:CVE-2015-1853 on Ubuntu 16.04 LTS (xenial) - medium.
Description:An attacker knowing that NTP hosts A and B are peering with each other (symmetric association) can send a packet with random timestamps to host A with source address of B which will set the NTP state variables on A to the values sent by the attacker. Host A will then send on its next poll to B a packet with originate timestamp that doesn't match the transmit timestamp of B and the packet will be dropped. If the attacker does this periodically for both hosts, they won't be able to synchronize to each other. Authentication using a symmetric key can fully protect against this attack, but in implementations following the NTPv3 (RFC 1305) or NTPv4 (RFC 5905) specification the state variables were updated even when the authentication check failed and the association was not protected.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-1853
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND NOT While related to the CVE in some way, the 'chrony' package in xenial is not affected (note: '2.1.1-1').
  • BACK