CVE-2016-1548
7.2
HIGH
CVSS 3.1
EPSS 3.8%
描述
An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time after the mode has been changed. ntpq gives no indication that the mode has been switched.
如何修補 CVE-2016-1548
要修補 CVE-2016-1548,請將受影響套件升級到下列已修補版本。
- —升級至 1:4.2.8p7+dfsg-1 或更新版本
CVE-2016-1548 正在被利用嗎?
低 — EPSS 為 3.8%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1:4.2.8p7+dfsg-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.2 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L |