NTP BUG 3010: remote configuration trustedkey/requestkey/controlkey values are not properly validated
Last update: April 22, 2024 18:49 UTC (7e7bd5857)
Summary
Description
If ntpd
was expressly configured to allow for remote configuration, a malicious user who knows the controlkey
for ntpq
or the requestkey
for ntpdc
(if mode7
is expressly enabled) can create a session with ntpd
and then send a crafted packet to ntpd
that will change the value of the trustedkey, controlkey
, or requestkey
to a value that will prevent any subsequent authentication with ntpd
until ntpd
is restarted.
Mitigation
Credit
This weakness was discovered by Yihan Lian of the Cloud Security Team, Qihoo 360.
Timeline