CVE-2016-4956: Input Validation
Published Jul 5, 2016
·Updated
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
Affected Software
38 affected components
Siemens SIMATIC NET CP 443-1 OPC UA
NTP ntp>=4.2.0<4.2.8
NTP ntp>=4.3.0<4.3.93
NTP ntp=4.2.8
NTP ntp=4.2.8-p1
NTP ntp=4.2.8-p1-beta1
NTP ntp=4.2.8-p1-beta2
NTP ntp=4.2.8-p1-beta3
NTP ntp=4.2.8-p1-beta4
NTP ntp=4.2.8-p1-beta5
NTP ntp=4.2.8-p1-rc1
NTP ntp=4.2.8-p1-rc2
NTP ntp=4.2.8-p2
NTP ntp=4.2.8-p2-rc1
NTP ntp=4.2.8-p2-rc2
NTP ntp=4.2.8-p2-rc3
NTP ntp=4.2.8-p3
NTP ntp=4.2.8-p3-rc1
NTP ntp=4.2.8-p3-rc2
NTP ntp=4.2.8-p3-rc3
NTP ntp=4.2.8-p4
NTP ntp=4.2.8-p5
NTP ntp=4.2.8-p6
NTP ntp=4.2.8-p7
Oracle Solaris=10
Oracle Solaris=11.3
SUSE Manager Proxy=2.1
SUSE Openstack Cloud=5
Novell Suse Manager=2.1
openSUSE Leap=42.1
openSUSE openSUSE=13.2
SUSE Linux Enterprise Desktop=12-sp1
SUSE Linux Enterprise Server=11-sp2
SUSE Linux Enterprise Server=11-sp3
SUSE Linux Enterprise Server=11-sp4
SUSE Linux Enterprise Server=12-sp1
Siemens Simatic Net Cp 443-1 Opc Ua Firmware
Siemens SIMATIC NET CP 443-1 OPC UA
Event History
Jul 5, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4956?
The severity of CVE-2016-4956 is classified as medium, indicating it can lead to a denial of service.
2
How do I fix CVE-2016-4956?
To fix CVE-2016-4956, you should upgrade to NTP version 4.2.8p8 or later.
3
What systems are affected by CVE-2016-4956?
CVE-2016-4956 affects NTP version 4.x prior to 4.2.8p8 and several Siemens products.
4
What type of vulnerability is CVE-2016-4956?
CVE-2016-4956 is a denial of service vulnerability caused by processing spoofed broadcast packets.
5
Is there a known exploit for CVE-2016-4956?
While specific exploits may not be publicly documented, the vulnerability allows remote attackers to induce a denial of service.