CVE-2018-8956

Name
CVE-2018-8956
Description
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Vendor Advisory http://www.ntp.org/
Third Party Advisory https://tools.ietf.org/html/rfc5905
Third Party Advisory https://nikhiltripathi.in/NTP_attack.pdf
Third Party Advisory https://arxiv.org/abs/2005.01783
CONFIRM https://security.netapp.com/advisory/ntap-20200518-0006/
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00044.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:ntp:ntp:4.2.8:p10:*:*:*:*:*:* ntp == None == 4.2.8

Vulnerable and fixed packages

Source package Branch Version Maintainer Status