ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-20563 ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T07:10:47.326Z

Reserved: 2018-03-23T00:00:00

Link: CVE-2018-8956

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-06T19:15:12.410

Modified: 2024-11-21T04:14:40.770

Link: CVE-2018-8956

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-05-06T00:00:00Z

Links: CVE-2018-8956 - Bugzilla

cve-icon OpenCVE Enrichment

No data.