← Back

CVE-2016-7426

nvd nist
Published: Jan 13, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

Affected (92)

Show all products
1 product
Ntp
1 product
Ubuntu Linux
6 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Eus
Enterprise Linux Server Tus
Enterprise Linux Workstation
1 product
Hpux Ntp
Configuration A
72 vulnerable
Vulnerable SoftwareAffected Versions
Ntp
From 4.2.6 to 4.2.8
From 4.3.0 to 4.3.94
Version 4.2.5 p203
Version 4.2.5 p204
Version 4.2.5 p205
Version 4.2.5 p206
Version 4.2.5 p207
Version 4.2.5 p208
Version 4.2.5 p209
Version 4.2.5 p210
Version 4.2.5 p211
Version 4.2.5 p212
Version 4.2.5 p213
Version 4.2.5 p214
Version 4.2.5 p215
Version 4.2.5 p216
Version 4.2.5 p217
Version 4.2.5 p218
Version 4.2.5 p219
Version 4.2.5 p220
Version 4.2.5 p221
Version 4.2.5 p222
Version 4.2.5 p223
Version 4.2.5 p224
Version 4.2.5 p225
Version 4.2.5 p226
Version 4.2.5 p227
Version 4.2.5 p228
Version 4.2.5 p229
Version 4.2.5 p230
Version 4.2.5 p231_rc1
Version 4.2.5 p232_rc1
Version 4.2.5 p233_rc1
Version 4.2.5 p234_rc1
Version 4.2.5 p235_rc1
Version 4.2.5 p236_rc1
Version 4.2.5 p237_rc1
Version 4.2.5 p238_rc1
Version 4.2.5 p239_rc1
Version 4.2.5 p240_rc1
Version 4.2.5 p241_rc1
Version 4.2.5 p242_rc1
Version 4.2.5 p243_rc1
Version 4.2.5 p244_rc1
Version 4.2.5 p245_rc1
Version 4.2.5 p246_rc1
Version 4.2.5 p247_rc1
Version 4.2.5 p248_rc1
Version 4.2.5 p249_rc1
Version 4.2.5 p250_rc1
Version 4.2.8
Version 4.2.8 p1-beta1
Version 4.2.8 p1-beta2
Version 4.2.8 p1-beta3
Version 4.2.8 p1-beta4
Version 4.2.8 p1-beta5
Version 4.2.8 p1-rc1
Version 4.2.8 p1-rc2
Version 4.2.8 p1
Version 4.2.8 p2-rc1
Version 4.2.8 p2-rc2
Version 4.2.8 p2-rc3
Version 4.2.8 p2
Version 4.2.8 p3-rc1
Version 4.2.8 p3-rc2
Version 4.2.8 p3-rc3
Version 4.2.8 p3
Version 4.2.8 p4
Version 4.2.8 p5
Version 4.2.8 p6
Version 4.2.8 p7
Version 4.2.8 p8
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.04
Configuration C
18 vulnerable
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
From b.11.31 to c.4.2.8.2.0

References (22)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Issue TrackingMitigationVendor Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.