CERT mailing list archives
Vulnerabilities Identified in Network Time Protocol Daemon (ntpd)
From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Wed, 08 Apr 2015 18:10:23 -0500
NCCIC / US-CERT National Cyber Awareness System: Vulnerabilities Identified in Network Time Protocol Daemon (ntpd) [ https://www.us-cert.gov/ncas/current-activity/2015/04/08/Vulnerabilities-Identified-Network-Time-Protocol-Daemon-ntpd ] 04/08/2015 05:47 PM EDT Original release date: April 08, 2015 The Network Time Foundation's NTP Project has released an update addressing multiple vulnerabilities in ntpd. Exploitation of these vulnerabilities may allow an attacker to conduct a man-in-the-middle attack or cause a denial of service condition. Users and administrators are encouraged to review Vulnerability Note VU#374268 [ http://www.kb.cert.org/vuls/id/374268 ] for more information and update to NTP 4.2.8p2 [ http://www.ntp.org/downloads.html ] if necessary. ________________________________________________________________________ This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy & Use [ http://www.us-cert.gov/privacy/ ] policy. ________________________________________________________________________ OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ http://www.us-cert.gov/related-resources ] STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ]
Current thread:
- Vulnerabilities Identified in Network Time Protocol Daemon (ntpd) US-CERT (Apr 08)
- <Possible follow-ups>
- Vulnerabilities Identified in Network Time Protocol Daemon (ntpd) US-CERT (Oct 22)