Total vulnerabilities in the database
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
Software | From | Fixed in |
---|---|---|
ntp / ntp | 4.2.8-p5 | 4.2.8-p5.x |
ntp / ntp | 4.2.8-p2 | 4.2.8-p2.x |
ntp / ntp | 4.2.8-p3 | 4.2.8-p3.x |
ntp / ntp | 4.2.8-p4 | 4.2.8-p4.x |
ntp / ntp | 4.2.8-p6 | 4.2.8-p6.x |
ntp / ntp | 4.2.8-p1 | 4.2.8-p1.x |
ntp / ntp | 4.2.8-p3-rc3 | 4.2.8-p3-rc3.x |
ntp / ntp | 4.2.8-p3-rc2 | 4.2.8-p3-rc2.x |
ntp / ntp | 4.2.8-p3-rc1 | 4.2.8-p3-rc1.x |
ntp / ntp | 4.2.8-p2-rc3 | 4.2.8-p2-rc3.x |
ntp / ntp | 4.2.8-p2-rc2 | 4.2.8-p2-rc2.x |
ntp / ntp | 4.2.8-p2-rc1 | 4.2.8-p2-rc1.x |
ntp / ntp | 4.2.8-p1-rc2 | 4.2.8-p1-rc2.x |
ntp / ntp | 4.2.8-p1-rc1 | 4.2.8-p1-rc1.x |
ntp / ntp | 4.2.8-p1-beta5 | 4.2.8-p1-beta5.x |
ntp / ntp | 4.2.8-p1-beta4 | 4.2.8-p1-beta4.x |
ntp / ntp | 4.2.8-p1-beta3 | 4.2.8-p1-beta3.x |
ntp / ntp | 4.2.8-p1-beta2 | 4.2.8-p1-beta2.x |
ntp / ntp | 4.2.8-p1-beta1 | 4.2.8-p1-beta1.x |
ntp / ntp | 4.3.0 | 4.3.92 |
ntp / ntp | 4.2.8 | 4.2.8.x |
ntp / ntp | 4.2.0 | 4.2.8 |
synology / diskstation_manager | 5.2 | 6.1.6-15266 |
synology / router_manager | 1.1 | 1.1.6-6931-3 |
synology / skynas | - | 6.1.5-15254 |
synology / virtual_diskstation_manager | - | 6.1.6-15266 |
synology / vs960hd_firmware | - | 2.2.3-1505 |
hpe / hpux-ntp | - | c.4.2.8.4.0 |