Menu
Exploits for dangerous network time protocol vulnerabilities can compromise systems

Exploits for dangerous network time protocol vulnerabilities can compromise systems

Systems administrators are urged to install critical patches that address remote code execution flaws in NTP

Remote code execution vulnerabilities in the standard implementation of the network time protocol (NTP) can be exploited by attackers to compromise servers, embedded devices and even critical infrastructure systems that run UNIX-like operating systems.

The flaws, which can be exploited by sending specially crafted packets to machines running a vulnerable version of the NTP daemon (ntpd), pose a greater threat to systems where the service runs under a highly privileged user account such as root.

However, even if the ntpd user has limited privileges, attackers could leverage other privilege escalation flaws to gain root access after exploiting the NTP flaws.

The Network Time Foundation, the organization that oversees the NTP project, has released version 4.2.8 of the standard protocol implementation to address the vulnerabilities. Some Linux distributions, including Red Hat have issued updated packages based on it, but others such as Ubuntu have yet to do so. Manufacturers of network security appliances and other embedded devices are likely still evaluating whether the flaws affect their products.

According to a security notice from the Network Time Foundation, the ntp 4.2.8 update fixes four buffer overflow vulnerabilities, tracked together as CVE-2014-9295 in the Common Vulnerabilities and Exposures database, and three other weaknesses in the protocol's cryptographic implementation and error handling. All issues were discovered by Neel Mehta and Stephen Roettger of the Google Security Team.

The U.S. government's Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) warned in an advisory Friday that exploit code for these vulnerabilities is publicly available already, which increases the risk associated with them. The organization advised industrial control system operators to evaluate the impact of the flaws in their respective environments, which may differ based on particular configurations.

"Ntpd typically does not have to run as root," said Johannes Ullrich, the CTO of the SANS Internet Storm Center, in a blog post. "Most Unix/Linux versions will configure NTP using a lower privileged user."

"Try to block inbound connections to ntp servers who do not have to be publicly reachable," Ullrich said. "However, be aware that simple stateful firewalls may not track UDP connections correctly and will allow access to internal NTP servers from any external IP if the NTP server recently established an outbound connection."

Systems administrators are advised the install the NTP patches as soon as they becomes available for their systems.

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags patchesSANS Technology InstituteGooglesecuritypatch managementNetwork Time FoundationRed HatExploits / vulnerabilitiesIndustrial Control Systems Cyber Emergency Response Teamintrusion

Featured

Slideshows

Educating from the epicentre - Why distributors are the pulse checkers of the channel

Educating from the epicentre - Why distributors are the pulse checkers of the channel

​As the channel changes and industry voices deepen, the need for clarity and insight heightens. Market misconceptions talk of an “under pressure” distribution space, with competitors in that fateful “race for relevance” across New Zealand. Amidst the cliched assumptions however, distribution is once again showing its strength, as a force to be listened to, rather than questioned. Traditionally, the role was born out of a need for vendors and resellers to find one another, acting as a bridge between the testing lab and the marketplace. Yet despite new technologies and business approaches shaking the channel to its very core, distributors remain tied to the epicentre - providing the voice of reason amidst a seismic industry shift. In looking across both sides of the vendor and partner fences, the middle concept of the three-tier chain remains centrally placed to understand the metrics of two differing worlds, as the continual pulse checkers of the local channel. This exclusive Reseller News Roundtable, in association with Dicker Data and rhipe, examined the pivotal role of distribution in understanding the health of the channel, educating from the epicentre as the market transforms at a rapid rate.

Educating from the epicentre - Why distributors are the pulse checkers of the channel
Kiwi channel reunites as After Hours kicks off 2017

Kiwi channel reunites as After Hours kicks off 2017

After Hours made a welcome return to the channel social calendar last night, with a bumper crowd of distributors, vendors and resellers descending on The Jefferson in Auckland to kickstart 2017. Photos by Maria Stefina.

Kiwi channel reunites as After Hours kicks off 2017
Arrow exclusively introduces Tenable Network Security to A/NZ channel

Arrow exclusively introduces Tenable Network Security to A/NZ channel

Arrow Electronics introduced Tenable Network Security to local resellers in Sydney last week, officially launching the distributor's latest security partnership across Australia and New Zealand. Representing the first direct distribution agreement locally for Tenable specifically, the deal sees Arrow deliver security solutions directly to mid-market and enterprise channel partners on both sides of the Tasman.

Arrow exclusively introduces Tenable Network Security to A/NZ channel
Show Comments