NTP 'ntp_crypto.c' Information Disclosure Vulnerability
BID:72583
Info
NTP 'ntp_crypto.c' Information Disclosure Vulnerability
| Bugtraq ID: | 72583 |
| Class: | Design Error |
| CVE: |
CVE-2014-9750 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2015 12:00AM |
| Updated: | Jul 11 2016 08:00PM |
| Credit: | Harlan Stenn |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.10 Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Server 11 SP1 LTSS Slackware Slackware Linux 14.1 Slackware Linux x86_64 -current Slackware Linux 14.1 x86_64 Slackware Linux 14.0 x86_64 Slackware Linux 14.0 Slackware Linux 13.37 x86_64 Slackware Linux 13.37 Slackware Linux 13.1 x86_64 Slackware Linux 13.1 Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux -current Oracle Linux 0 Oracle Enterprise Linux 7 Meinberg Network Time Protocol 4.2.8 Meinberg Network Time Protocol 4.2.7p230 Meinberg Network Time Protocol 4.2.7p11 Meinberg Network Time Protocol 4.2.7p10 Meinberg Network Time Protocol 4.2.7 Meinberg Network Time Protocol 4.2.6 Meinberg Network Time Protocol 4.2.5 Meinberg Network Time Protocol 4.2.4 Meinberg Network Time Protocol 4.2.2 Meinberg Network Time Protocol 4.2.0 Meinberg Network Time Protocol 4.1.0 Meinberg Network Time Protocol 4.0 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Juniper vGW 0 Juniper NSMXpress 2012.2R10 Juniper NSM Server Software 0 Juniper NSM Series Appliances 0 Juniper JUNOS Space 0 Juniper Junos OS 0 IBM Vios 2.2.3 IBM Vios 2.2.1 4 IBM Vios 2.2 IBM Vios 2.2.4.0 IBM Vios 2.2.3.50 IBM Vios 2.2.3.4 IBM Vios 2.2.3.3 IBM Vios 2.2.3.2 IBM Vios 2.2.2.6 IBM Vios 2.2.2.5 IBM Vios 2.2.2.4 IBM Vios 2.2.2.0 IBM Vios 2.2.1.9 IBM Vios 2.2.1.8 IBM Vios 2.2.1.3 IBM Vios 2.2.1.1 IBM Vios 2.2.1.0 IBM Vios 2.2.0.13 IBM Vios 2.2.0.12 IBM Vios 2.2.0.11 IBM Vios 2.2.0.10 IBM SmartCloud Provisioning for Software Virtual Appliance 2.1 IBM SmartCloud Entry 3.2 fix pack 14 IBM SmartCloud Entry 3.2 fix pack 13 IBM SmartCloud Entry 3.2 Fix Pack 11 IBM SmartCloud Entry 3.2 IBM SmartCloud Entry 3.1 FP 9 IBM SmartCloud Entry 3.1 fix pack 13 IBM SmartCloud Entry 3.1 Fix Pack 10 IBM SmartCloud Entry 3.1 IBM SmartCloud Entry 2.4 Fix Pack 2 IBM SmartCloud Entry 2.3 Fix Pack 2 IBM SmartCloud Entry 2.3 Fix Pack 1 IBM SmartCloud Entry 2.3 Appliance fix pack 4 IBM SmartCloud Entry 2.2 Fix Pack 2 IBM SmartCloud Entry 2.2 Fix Pack 1 IBM SmartCloud Entry 2.2 Appliance fix pack 4 IBM SmartCloud Entry 2.2 IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 Appliance FP IBM SmartCloud Entry 3.2.0.4 IBM SmartCloud Entry 3.2.0.3 IBM SmartCloud Entry 3.2.0.2 IBM SmartCloud Entry 3.2.0.1 IBM SmartCloud Entry 3.2.0.0 IBM SmartCloud Entry 3.2.0 fix pack 9 IBM SmartCloud Entry 3.2.0 fix pack 8 IBM SmartCloud Entry 3.2.0 fix pack 10 IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 Appliance FP IBM SmartCloud Entry 3.1.0.4 IBM SmartCloud Entry 3.1.0.3 IBM SmartCloud Entry 3.1.0.2 IBM SmartCloud Entry 3.1.0.1 IBM SmartCloud Entry 3.1.0.0 IBM SmartCloud Entry 3.1.0 fix pack 9 IBM SmartCloud Entry 3.1.0 fix pack 8 IBM SmartCloud Entry 2.4.0.3 Appliance FP IBM SmartCloud Entry 2.4.0 fix pack 1 IBM SmartCloud Entry 2.4.0 IBM SmartCloud Entry 2.3.0.3 Appliance FP IBM SmartCloud Entry 2.3.0 IBM SmartCloud Entry 2.2.0.3 Appliance FP IBM Smart Analytics System 7710 0 IBM Smart Analytics System 7700 0 IBM Smart Analytics System 7600 0 IBM Smart Analytics System 5710 0 IBM Smart Analytics System 5600 3 IBM Smart Analytics System 5600 2 IBM Smart Analytics System 5600 1 IBM Smart Analytics System 2050 0 IBM Smart Analytics System 1050 0 IBM Security Proventia Network Multi-Function Security System 4.6 IBM Security Network Protection 5.3 IBM Security Network Protection 5.2.0 IBM Security Identity Manager Virtual Appliance 7.0.0.3 IBM Security Identity Manager Virtual Appliance 7.0.0.2 IBM Security Identity Manager Virtual Appliance 7.0.0.1 IBM Security Identity Manager Virtual Appliance 7.0.0.0 IBM Security Access Manager for Web 8.0 IBM Security Access Manager for Web 7.0 IBM Security Access Manager for Mobile 8.0.1 IBM Security Access Manager for Mobile 8.0.1.3 IBM Security Access Manager for Mobile 8.0.1.2 IBM Security Access Manager for Mobile 8.0.1.1 IBM Security Access Manager for Mobile 8.0.0.5 IBM Security Access Manager for Mobile 8.0.0.4 IBM Security Access Manager for Mobile 8.0.0.3 IBM Security Access Manager for Mobile 8.0.0.2 IBM Security Access Manager for Mobile 8.0.0.1 IBM Security Access Manager for Mobile 8.0.0.0 IBM Security Access Manager 9.0 IBM QLogic Virtual Fabric Extension Module for IBM BladeCenter 9.0 IBM QLogic 8Gb Intelligent Pass-thru Module and SAN Switch Module 7.10 IBM PureData System for Operational Analytics 1.1 (A1801) IBM PureData System for Operational Analytics 1.0 (A1791) IBM Power HMC 8.3.0.0 IBM Power HMC 8.2.0.0 IBM Power HMC 8.1.0.0 IBM InfoSphere Balanced Warehouse C4000 0 IBM InfoSphere Balanced Warehouse C3000 0 IBM InfoSphere Balanced Warehouse C4000 IBM InfoSphere Balanced Warehouse C3000 IBM Flex System p460 Compute Node (7895-43X) 783.11: 01AF783_027_ IBM Flex System p460 Compute Node (7895-43X) 783.10: 01AF783_026_ IBM Flex System p460 Compute Node (7895-43X) 783.01: 01AF783_022_ IBM Flex System p460 Compute Node (7895-43X) 783.00: 01AF783_021_ IBM Flex System p460 Compute Node (7895-42X) 783.11: 01AF783_027_ IBM Flex System p460 Compute Node (7895-42X) 783.10: 01AF783_026_ IBM Flex System p460 Compute Node (7895-42X) 783.01: 01AF783_022_ IBM Flex System p460 Compute Node (7895-42X) 783.00: 01AF783_021_ IBM Flex System p270 Compute Node (7954-24X) 783.11: 01AF783_027_ IBM Flex System p270 Compute Node (7954-24X) 783.10: 01AF783_026_ IBM Flex System p270 Compute Node (7954-24X) 783.01: 01AF783_022_ IBM Flex System p270 Compute Node (7954-24X) 783.00: 01AF783_021_ IBM Flex System p260 Compute Node (7895-23X) 783.11: 01AF783_027_ IBM Flex System p260 Compute Node (7895-23X) 783.10: 01AF783_026_ IBM Flex System p260 Compute Node (7895-23X) 783.01: 01AF783_022_ IBM Flex System p260 Compute Node (7895-23X) 783.00: 01AF783_021_ IBM Flex System p260 Compute Node (7895-23A) 783.11: 01AF783_027_ IBM Flex System p260 Compute Node (7895-23A) 783.10: 01AF783_026_ IBM Flex System p260 Compute Node (7895-23A) 783.01: 01AF783_022_ IBM Flex System p260 Compute Node (7895-23A) 783.00: 01AF783_021_ IBM Flex System p260 Compute Node (7895-22X) 783.11: 01AF783_027_ IBM Flex System p260 Compute Node (7895-22X) 783.10: 01AF783_026_ IBM Flex System p260 Compute Node (7895-22X) 783.01: 01AF783_022_ IBM Flex System p260 Compute Node (7895-22X) 783.00: 01AF783_021_ IBM Flex System p24L Compute Node (1457-7FL) 783.11: 01AF783_027_ IBM Flex System p24L Compute Node (1457-7FL) 783.10: 01AF783_026_ IBM Flex System p24L Compute Node (1457-7FL) 783.01: 01AF783_022_ IBM Flex System p24L Compute Node (1457-7FL) 783.00: 01AF783_021_ IBM Flex System Manager 1.3.2 0 IBM Flex System Manager 1.3.3.0 IBM Flex System Manager 1.3.1.0 IBM Flex System Manager 1.3.0.1 IBM Flex System Manager 1.3.0.0 IBM Flex System Manager 1.2.1.0 IBM Flex System Manager 1.2.0.0 IBM Flex System Manager 1.1.0.0 IBM Flex System FC3171 8Gb SAN Switch and SAN Pass-thru 9.1.0.00 IBM Flex System Chassis Management Module (CMM) 0 IBM DS8870 R7.2 IBM DS8800 R6.3 SP9 IBM DS8700 R6.3 SP9 IBM Aix 7.1.4 IBM Aix 7.1.3 IBM AIX 7.1.2 IBM AIX 7.1.1 IBM AIX 7.1 6 IBM AIX 7.1 IBM Aix 6.1.9 IBM AIX 6.1.8 IBM AIX 6.1.7 5 IBM AIX 6.1.7 IBM AIX 6.1.6 8 IBM AIX 6.1.6 IBM AIX 6.1.5 IBM AIX 6.1.4 IBM AIX 6.1.3 IBM AIX 6.1.2 IBM AIX 6.1.1 IBM Aix 7.1.4.1 IBM Aix 7.1.3.5 IBM Aix 7.1.2.6 IBM AIX 7.1.2.15 IBM AIX 7.1.1.5 IBM AIX 7.1.1.16 IBM Aix 6.1.9.6 IBM Aix 6.1.9.5 IBM Aix 6.1.8.7 IBM Aix 6.1.8.6 IBM AIX 6.1.8.15 IBM AIX 6.1.7.16 HP HP-UX B.11.31 HP HP-UX B.11.23 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Cisco WebEx Social 0 Cisco Virtual Security Gateway 0 Cisco Videoscape Conductor 0 Cisco Videoscape Back Office (VBO) 0 Cisco Video Delivery System Recorder 0 Cisco Unity Connection 0 Cisco Unified Communications Domain Manager 0 Cisco UCS Invicta Series 0 Cisco TelePresence TX 9000 Series 0 Cisco TelePresence System 500-37 0 Cisco TelePresence System 500-32 0 Cisco TelePresence System 3000 Series 0 Cisco TelePresence System 1300 0 Cisco TelePresence System 1100 0 Cisco TelePresence System 1000 0 Cisco TelePresence 1310 0 Cisco SCOS (Service Control Operating System) 0 Cisco Quantum SON Suite 0 Cisco Prime LAN Management Solution 0 Cisco Physical Access Manager 0 Cisco Network Configuration and Change Management Service 0 Cisco IM and Presence Service (CUPS) 0 Cisco Common Services Platform Collector 0 Cisco Cloud Object Store (COS) 0 Cisco Cisco IronPort Encryption Appliance (IEA) 0 Cisco Cisco Edge 300 Digital Media Player 0 |
| Not Vulnerable: |
Meinberg Network Time Protocol 4.2.8p1 IBM QLogic Virtual Fabric Extension Module for IBM BladeCenter 9.0.3.16.00 IBM QLogic 8Gb Intelligent Pass-thru Module and SAN Switch Module 7.10.1.38.00 IBM Flex System p460 Compute Node (7895-43X) 783.20: 01AF783_030_ IBM Flex System p460 Compute Node (7895-42X) 783.20: 01AF783_030_ IBM Flex System p270 Compute Node (7954-24X) 783.20: 01AF783_030_ IBM Flex System p260 Compute Node (7895-23X) 783.20: 01AF783_030_ IBM Flex System p260 Compute Node (7895-23A) 783.20: 01AF783_030_ IBM Flex System p260 Compute Node (7895-22X) 783.20: 01AF783_030_ IBM Flex System p24L Compute Node (1457-7FL) 783.20: 01AF783_030_ IBM Flex System FC3171 8Gb SAN Switch and SAN Pass-thru 9.1.8.01.00 |
Discussion
NTP 'ntp_crypto.c' Information Disclosure Vulnerability
NTP is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
NTP is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
Exploit / POC
NTP 'ntp_crypto.c' Information Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NTP 'ntp_crypto.c' Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Slackware Linux 13.1
Slackware Linux x86_64 -current
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Slackware Linux 13.1
-
Slackware ntp-4.2.8p4-i486-1_slack13.1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/ ntp-4.2.8p4-i486-1_slack13.1.txz
Slackware Linux x86_64 -current
-
Slackware ntp-4.2.8p4-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ n/ntp-4.2.8p4-x86_64-1.txz
References
NTP 'ntp_crypto.c' Information Disclosure Vulnerability
References:
References:
- Bug 2671 - vallen is not validated, leading to potential info leak (NTP)
- NTP Homepage (ntp.org)
- Out of Cycle Security Bulletin: Multiple vulnerabilities in NTP (Juniper)
- HPSBUX03240 SSRT101872 rev.1 - HP-UX Running NTP, Remote Execution of Code, Deni (HP)
- IBM Advisory isg3T1022814 (IBM)
- IBM Advisory MIGR-5098944 (IBM)
- IBM Advisory ssg1S1005137 (IBM)
- IBM Advisory swg21966675 (IBM)
- IBM Advisory swg21967791 (IBM)
- IBM Advisory swg21972266 (IBM)
- IBM Advisory swg21974652 (IBM)
- IBM InfoSphere Balanced Warehouse C3000, C4000, IBM Smart Analytics System 1050, (IBM)
- ntp4_advisory.asc: IBM SECURITY ADVISORY (IBM)
- Ref: linuxbulletinoct2015-2719645 Oracle Linux Bulletin - October 2015 Revision (Oracle)
- Security Bulletin: Flex System Power Compute Node Firmware affected by vulnerabi (IBM)
- Security Bulletin: Multiple vulnerabilities in ntp affect IBM Flex System Manage (IBM)
- Security Bulletin: Multiple vulnerabilities in NTP, Hivex, glibc, libuser, BIND (IBM)
- Security Bulletin: Vulnerabilities in NTP affect IBM Security Network Protection (IBM)
- Security Bulletin: Vulnerabilities in NTP Affect Power Hardware Management Conso (IBM)
- Security Bulletin:IBM Security Proventia Network Multi-Function Security System( (IBM)
- swg21975967: IBM Security Access Manager for Mobile is affected by multiple NTP (IBM)
- VU#852879 Network Time Protocol daemon (ntpd) contains multiple vulnerabilities (CERT)