|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
 |
Vulnerability Note VU#568372
NTP mode 7 denial-of-service vulnerability
OverviewNTP contains a vulnerability in the handling of mode 7 requests, which can result in a denial-of-service condition.
I. DescriptionNTP mode 7 (MODE_PRIVATE) is used by the ntpdc query and control utility. In contrast, ntpq uses NTP mode 6 (MODE_CONTROL), while routine NTP time transfers use modes 1 through 5. Upon receipt of an incorrect mode 7 request or a mode 7 error response from an address that is not listed in a "restrict ... noquery" or "restrict ... ignore" segment, ntpd will reply with a mode 7 error response and log a message.
If an attacker spoofs the source address of ntpd host A in a mode 7 response packet sent to ntpd host B, both A and B will continuously send each other error responses, for as long as those packets get through.
If an attacker spoofs an address of ntpd host A in a mode 7 response packet sent to ntpd host A, then host A will respond to itself endlessly, consuming CPU and logging excessively.
II. ImpactA remote, unauthenticated attacker may be able to cause a denial-of-service condition on a vulnerable NTP server.
III. SolutionApply an update
This issue is addressed in NTP 4.2.4p8. Please check with your vendor for an update, or you may download NTP 4.2.4p8 from ntp.org.
Configure NTP to limit source addresses
By using "restrict ... noquery" or "restrict ... ignore" entries in the ntp.conf file, ntpd can be configured to limit the source addresses to which it will respond.
Filter NTP mode 7 packets that specify source and destination port 123
In most cases, ntpdc mode 7 requests will have either a source or destination port of 123, but not both.
Use anti-spoofing IP address filters
RFC 2827 (BCP 38) describes network ingress filtering, which can prevent UDP traffic claiming to be from a local address from entering your network from an outside source. Some ISPs may employ unicast reverse path filtering (uRPF) to limit the spoofed traffic that can enter your network.
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
| 3com Inc | Unknown | 2009-10-26 | 2009-10-26 |
| ACCESS | Unknown | 2009-10-26 | 2009-10-26 |
| Alcatel-Lucent | Unknown | 2009-10-26 | 2009-10-26 |
| Apple Inc. | Vulnerable | 2009-10-26 | 2009-10-27 |
| AT&T | Unknown | 2009-10-26 | 2009-10-26 |
| Avaya, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Barracuda Networks | Unknown | 2009-10-26 | 2009-10-26 |
| Belkin, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Borderware Technologies | Unknown | 2009-10-26 | 2009-10-26 |
| Charlotte's Web Networks | Unknown | 2009-10-26 | 2009-10-26 |
| Check Point Software Technologies | Unknown | 2009-10-26 | 2009-10-26 |
| Cisco Systems, Inc. | Vulnerable | 2009-10-26 | 2009-12-13 |
| Clavister | Unknown | 2009-10-26 | 2009-10-26 |
| Computer Associates | Not Vulnerable | 2009-10-26 | 2010-04-27 |
| Conectiva Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Cray Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| D-Link Systems, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Debian GNU/Linux | Vulnerable | 2009-10-26 | 2009-12-08 |
| EMC Corporation | Unknown | 2009-10-26 | 2009-10-26 |
| Engarde Secure Linux | Unknown | 2009-10-26 | 2009-10-26 |
| Enterasys Networks | Unknown | 2009-10-26 | 2009-10-26 |
| Ericsson | Unknown | 2009-10-26 | 2009-10-26 |
| eSoft, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Extreme Networks | Not Vulnerable | 2009-10-26 | 2010-02-03 |
| F5 Networks, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Fedora Project | Unknown | 2009-10-26 | 2009-10-26 |
| Force10 Networks, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Fortinet, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Foundry Networks, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| FreeBSD, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Fujitsu | Unknown | 2009-10-26 | 2009-10-26 |
| Gentoo Linux | Vulnerable | 2009-10-26 | 2009-12-10 |
| Global Technology Associates | Unknown | 2009-10-26 | 2009-10-26 |
| Hewlett-Packard Company | Unknown | 2009-10-26 | 2009-10-26 |
| Hitachi | Unknown | 2009-10-26 | 2009-10-26 |
| IBM Corporation | Unknown | 2009-10-26 | 2009-10-26 |
| IBM eServer | Unknown | 2009-10-26 | 2009-10-26 |
| Infoblox | Unknown | 2009-10-26 | 2009-10-26 |
| Intel Corporation | Unknown | 2009-10-26 | 2009-10-26 |
| Internet Security Systems, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Intoto | Unknown | 2009-10-26 | 2009-10-26 |
| IP Filter | Unknown | 2009-10-26 | 2009-10-26 |
| IP Infusion, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Juniper Networks, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Luminous Networks | Unknown | 2009-10-26 | 2009-10-26 |
| m0n0wall | Unknown | 2009-10-26 | 2009-10-26 |
| Mandriva S. A. | Unknown | 2009-10-26 | 2009-10-26 |
| McAfee | Unknown | 2009-10-26 | 2009-10-26 |
| Meinberg Funkuhren GmbH & Co. KG | Vulnerable | | 2009-12-16 |
| Microsoft Corporation | Not Vulnerable | 2009-10-26 | 2010-04-05 |
| MontaVista Software, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Multitech, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| NEC Corporation | Unknown | 2009-10-26 | 2009-10-26 |
| NetApp | Unknown | 2009-10-26 | 2009-10-26 |
| NetBSD | Unknown | 2009-10-26 | 2009-10-26 |
| netfilter | Unknown | 2009-10-26 | 2009-10-26 |
| Nokia | Unknown | 2009-10-26 | 2009-10-26 |
| Nortel Networks, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Novell, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Openwall GNU/*/Linux | Unknown | 2009-10-26 | 2009-10-26 |
| PePLink | Not Vulnerable | 2009-10-26 | 2009-12-04 |
| Process Software | Unknown | 2009-10-26 | 2009-10-26 |
| Q1 Labs | Unknown | 2009-10-26 | 2009-10-26 |
| QNX Software Systems Inc. | Vulnerable | 2009-10-26 | 2009-12-07 |
| Quagga | Unknown | 2009-10-26 | 2009-10-26 |
| RadWare, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Red Hat, Inc. | Vulnerable | 2009-10-26 | 2009-12-08 |
| Redback Networks, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| SafeNet | Not Vulnerable | 2009-10-26 | 2009-10-28 |
| Secureworx, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Silicon Graphics, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Slackware Linux Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| SmoothWall | Unknown | 2009-10-26 | 2009-10-26 |
| Snort | Unknown | 2009-10-26 | 2009-10-26 |
| Soapstone Networks | Unknown | 2009-10-26 | 2009-10-26 |
| Sony Corporation | Unknown | 2009-10-26 | 2009-10-26 |
| Sourcefire | Unknown | 2009-10-26 | 2009-10-26 |
| Stonesoft | Unknown | 2009-10-26 | 2009-10-26 |
| Sun Microsystems, Inc. | Vulnerable | 2009-10-26 | 2010-01-22 |
| SUSE Linux | Unknown | 2009-10-26 | 2009-10-26 |
| Symantec | Unknown | 2009-10-26 | 2009-10-26 |
| The SCO Group | Vulnerable | 2009-10-26 | 2009-10-29 |
| TippingPoint Technologies Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Turbolinux | Unknown | 2009-10-26 | 2009-10-26 |
| U4EA Technologies, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Ubuntu | Vulnerable | 2009-10-26 | 2009-12-09 |
| Unisys | Unknown | 2009-10-26 | 2009-10-26 |
| VMware | Unknown | 2009-10-26 | 2009-10-26 |
| Vyatta | Unknown | 2009-10-26 | 2009-10-26 |
| Watchguard Technologies, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| Wind River Systems, Inc. | Unknown | 2009-10-26 | 2009-10-26 |
| ZyXEL | Unknown | 2009-10-26 | 2009-10-26 |
References
https://support.ntp.org/bugs/show_bug.cgi?id=1331
http://tools.ietf.org/html/rfc2827
http://tools.ietf.org/html/rfc3704
http://www.ntp.org/downloads.html
http://www.ubuntu.com/usn/USN-867-1
http://security-tracker.debian.org/tracker/CVE-2009-3563
http://tools.cisco.com/security/center/viewAlert.x?alertId=19540
Credit
Thanks to Harlan Stenn for reporting this vulnerability.
This document was written by Will Dormann, based on information provided by Harlan Stenn.
Other Information
| Date Public: | 2009-12-08 |
| Date First Published: | 2009-12-08 |
| Date Last Updated: | 2010-04-27 |
| CERT Advisory: | |
| CVE-ID(s): | CVE-2009-3563 |
| NVD-ID(s): | CVE-2009-3563 |
| US-CERT Technical Alerts: | |
| Metric: | 0.00 |
| Document Revision: | 30 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
|