4.2.8p4 Release Announcement
Last update: March 28, 2023 21:06 UTC (4798c81ce)
NTF’s NTP Project has been notified of the following 13 low- and medium-severity vulnerabilities that are fixed in ntp-4.2.8p4, released on Wednesday, 21 October 2015:
The only generally-exploitable bug in the above list is the crypto-NAK bug, which has a CVSS2 score of 6.4.
Additionally, three bugs that have already been fixed in ntp-4.2.8 but were not fixed in ntp-4.2.6 as it was EOL’d have a security component, but are all below 1.8 CVSS score, so we’re reporting them here:
Timeline:
- 2015 Oct 21: Public release
- 2015 Oct 20: CERT & Mitre updated with final drafts of announcement
- 2015 Oct 19: NAK bug addition and new CVE#s announced to CERT
- 2015 Oct 17: Advance notification of NAK bug being added was sent to Institutional members
- 2015 Oct 14: pre-release patch availability announced to CERT
- 2015 Oct 9: notification of public release date change to 21 Oct sent to members and reporters and Mitre
- 2015 Oct 6: Early Access Program Release: Premier and Partner Institutional Members
- 2015 Aug 26: Initial notification of 2909; analysis begins
- 2015 Aug 26: CVE number clarification requested from Mitre
- 2015 Aug 26: Notification to Institutional Members for 1593, 1774, 2382, 2899, and 2902
- 2015 Aug 20: Initial notification of 2902; analysis begins
- 2015 Aug 11: Initial notification of 2899; analysis begins