PublicDateAtUSN: 2017-01-13 Candidate: CVE-2016-7431 PublicDate: 2017-01-13 16:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7431 https://ubuntu.com/security/notices/USN-3349-1 Description: NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression. Ubuntu-Description: Notes: mdeslaur> ntp-4.2.8p8 and ntp-4.3.93 Bugs: http://support.ntp.org/bin/view/Main/NtpBug3102 Priority: medium Discovered-by: Sharon Goldberg and Aanchal Malhotra Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N [5.3 MEDIUM] Patches_ntp: upstream: http://bk1.ntp.org/ntp-stable/?PAGE=cset&REV=57ff44d0W6suoUHdd2ZvRM3z87j2QA upstream_ntp: released (1:4.2.8p9+dfsg-1, 4.2.8p9) precise_ntp: not-affected (1:4.2.6.p3+dfsg-1ubuntu3.11) precise/esm_ntp: not-affected (1:4.2.6.p3+dfsg-1ubuntu3.11) trusty_ntp: not-affected (1:4.2.6.p5+dfsg-3ubuntu2.14.04.10) trusty/esm_ntp: not-affected (1:4.2.6.p5+dfsg-3ubuntu2.14.04.10) vivid/stable-phone-overlay_ntp: ignored (reached end-of-life) vivid/ubuntu-core_ntp: DNE xenial_ntp: not-affected (1:4.2.8p4+dfsg-3ubuntu5.3) esm-infra/xenial_ntp: not-affected (1:4.2.8p4+dfsg-3ubuntu5.3) yakkety_ntp: released (1:4.2.8p8+dfsg-1ubuntu2.1) zesty_ntp: not-affected (1:4.2.8p9+dfsg-2ubuntu1) devel_ntp: not-affected (1:4.2.8p9+dfsg-2ubuntu1)