ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
| Software | From | Fixed in |
|---|---|---|
| ntp / ntp | 4.3.92 | 4.3.92.x |
| ntp / ntp | 4.2.8-p7 | 4.2.8-p7.x |
| oracle / solaris | 11.3 | 11.3.x |
| oracle / solaris | 10 | 10.x |
| novell / suse_manager | 2.1 | 2.1.x |
| suse / linux_enterprise_server | 11-sp4 | 11-sp4.x |
| suse / openstack_cloud | 5 | 5.x |
| suse / manager_proxy | 2.1 | 2.1.x |
| suse / linux_enterprise_server | 11-sp3 | 11-sp3.x |
| suse / linux_enterprise_server | 12-sp1 | 12-sp1.x |
| suse / linux_enterprise_server | 11-sp2 | 11-sp2.x |
| suse / linux_enterprise_desktop | 12-sp1 | 12-sp1.x |
| opensuse / leap | 42.1 | 42.1.x |
| opensuse / opensuse | 13.2 | 13.2.x |