PublicDateAtUSN: 2015-10-22 Candidate: CVE-2015-5300 PublicDate: 2017-07-21 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5300 http://www.cs.bu.edu/~goldbe/NTPattack.html https://ubuntu.com/security/notices/USN-2783-1 Description: The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart). Ubuntu-Description: Notes: mdeslaur> as of 2015-10-22, not yet fixed upstream mdeslaur> patch in redhat bug, but improved patch in comment #3 is mdeslaur> restricted Bugs: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-5300 Priority: medium Discovered-by: Aanchal Malhotra, Isaac E. Cohen, and Sharon Goldberg Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_ntp: vendor: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-5300 vendor: http://pkgs.fedoraproject.org/cgit/ntp.git/plain/ntp-4.2.6p5-cve-2015-5300.patch upstream_ntp: needs-triage precise_ntp: released (1:4.2.6.p3+dfsg-1ubuntu3.6) trusty_ntp: released (1:4.2.6.p5+dfsg-3ubuntu2.14.04.5) trusty/esm_ntp: released (1:4.2.6.p5+dfsg-3ubuntu2.14.04.5) vivid_ntp: released (1:4.2.6.p5+dfsg-3ubuntu6.2) wily_ntp: released (1:4.2.6.p5+dfsg-3ubuntu8.1) devel_ntp: released (1:4.2.6.p5+dfsg-3ubuntu8.1) vivid/stable-phone-overlay_ntp: released (1:4.2.6.p5+dfsg-3ubuntu6.2) vivid/ubuntu-core_ntp: DNE