Re: [request] ntp upgrade

From: Tom Evans <tevans.uk_at_googlemail.com>
Date: Wed, 27 Nov 2013 16:06:18 +0000
On Wed, Nov 27, 2013 at 3:29 PM, Cristiano Deana
<cristiano.deana_at_gmail.com> wrote:
> Hi,
>
> is it possible to include in base system of the upcoming 10.0 the new
> version of ntp (4.2.7 instead of 4.2.4)?
>
> There is a bug in older versions (< 4.2.7) who allows attacker use an ntp
> server to DDoS. This has been corrected in new version:
> https://cert.litnet.lt/en/docs/ntp-distributed-reflection-dos-attacks
>
> This attack seems to be increasing in the last few weeks.
>
> net/ntp-devel is Ok.
>
> Thank you, sorry for my basic english.
>

ntp 4.2.4p8 isn't vulnerable.

http://www.cvedetails.com/vulnerability-list/vendor_id-2153/NTP.html

The reflection attack is the first in the list, 4.2.4p7 and below are affected.

Cheers

Tom
Received on Wed Nov 27 2013 - 15:06:20 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:40:44 UTC