NTP Denial of Service Vulnerability (CVE-2015-5219)
NTP Denial of Service Vulnerability (CVE-2015-5219)
Release date:
Updated on:
Affected Systems:
NTP 4.x
Description:
Bugtraq id: 76473
CVE (CAN) ID: CVE-2015-5219
Network Time Protocol (NTP) is a Protocol used to synchronize computer Time. It can synchronize computers with their servers or clock sources (such as quartzels and GPS.
NTP will cause sntp suspension when processing constructed NTP packets. Remote attackers can exploit this vulnerability to cause DOS.
<* Source: Miroslav Lichvar
*>
Suggestion:
Vendor patch:
NTP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://bk1.ntp.org/ntp-dev? PAGE = patch & REV = 51786731Gr4-NOrTBC_a_uXO4wuGhg
Https://github.com/ntp-project/ntp/commit/5f295cd05c3c136d39f5b3e500a2d781bdbb59c8
CentOS NTP server installation and configuration
NTP servers in Linux
NTP client configurations for multiple operating systems
Build an enterprise-level NTP Time Server
Set up an ntp time synchronization server in Linux
Enable NTP time server in CentOS 6.3
This article permanently updates the link address: