NTP users are strongly urged to take immediate action to ensure that their NTP daemons are not susceptible to being used in distributed denial-of-service (DDoS) attacks. Please also take this opportunity to defeat denial-of-service attacks by implementing Ingress and Egress filtering through BCP38.
ntp-4.2.8p15was released on 23 June 2020. It addresses 1 medium-severity security issue in ntpd, and provides 13 non-security bugfixes over 4.2.8p13.
Please see the NTP Security Notice for vulnerability and mitigation details.Are you using Autokey in production? If so, please contact Harlan - he's got some questions for you.
ntpqis a monitoring and control program for
decodearr()is an internal function of
ntpqthat is used to -- wait for it -- decode an array in a response string when formatted data is being displayed. This is a problem in affected versions of
ntpqif a maliciously-altered
ntpdreturns an array result that will trip this bug, or if a bad actor is able to read an
ntpqrequest on its way to a remote
ntpdserver and forge and send a response before the remote
ntpdsends its response. It's potentially possible that the malicious data could become injectable/executable code.