[原文]The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.

[CNNVD]NTPD 不安全权限漏洞(CNNVD-200509-032)

        xntpd ntp (ntpd)后台进程4.2.0b以前的版本,当以-u选项运行并且使用一字符串指定组时,使用的是用户的组ID而非组。这使得xntpd可以以与预定权限不同的权限运行。

CVSS分值: 4.6 [中等(MEDIUM)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: PARTIAL [可能会导致系统文件被修改]
可用性影响: PARTIAL [可能会导致性能下降或中断资源访问]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: LOCAL [漏洞利用需要具有物理访问权限或本地帐户]
身份认证: NONE [漏洞利用无需身份认证]

- OVAL (用于检测的技术细节)

The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group

MITRE
NVD
CNNVD

XF  ntp-incorrect-group-permissions(22035)
VUPEN  ADV-2005-1561
BID  14673

NTPD 不安全权限漏洞
中危 设计错误
2005-09-02 00:00:00 2005-10-20 00:00:00
        xntpd ntp (ntpd)后台进程4.2.0b以前的版本,当以-u选项运行并且使用一字符串指定组时,使用的是用户的组ID而非组。这使得xntpd可以以与预定权限不同的权限运行。

Debian Linux Security Advisory 801-1 (PacketStormID:F39849)
2005-09-07 00:00:00

Debian Security Advisory DSA 801-1 - SuSE developers discovered that ntp confuses the given group id with the group id of the given user when called with a group id on the commandline that is specified as a string and not as a numeric gid, which causes ntpd to run with different privileges than intended.

Debian Security Advisory DSA 801-1                                        Martin Schulze
September 5th, 2005           
Package        : ntp
Vulnerability  : programming error
Problem-Type   : local
Debian-specific: no
CVE ID         : CAN-2005-2496

SuSE developers discovered that ntp confuses the given group id with
the group id of the given user when called with a group id on the
commandline that is specified as a string and not as a numeric gid,
which causes ntpd to run with different privileges than intended.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) this problem has been fixed in
version 4.2.0a+stable-2sarge1.

The unstable distribution (sid) is not affected by this problem.

We recommend that you upgrade your ntp-server package.

NTP ntpd -u Group Permission Weakness

Upgrade to version 4.2.0b or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

NTPD Insecure Privileges Vulnerability
Design Error 14673
Yes No
2005-08-27 12:00:00 2006-09-05 11:33:00
Thomas Biege <> is credited with the discovery of this vulnerability.

- 受影响的程序版本

Ubuntu Ubuntu Linux 4.1 ppc
Ubuntu Ubuntu Linux 4.1 ia64
Ubuntu Ubuntu Linux 4.1 ia32
RedHat Enterprise Linux WS 4
RedHat Enterprise Linux ES 4
RedHat Desktop 4.0
Red Hat Fedora Core3
Red Hat Enterprise Linux AS 4
NTP NTPd 4.2 .0a
NTP NTPd 4.2
NTP NTPd 4.1
NTP NTPd 4.0
NetBSD NetBSD 2.1
NetBSD NetBSD 2.0.3
NetBSD NetBSD 2.0.2
NetBSD NetBSD 2.0.1
NetBSD NetBSD 1.6.2
NetBSD NetBSD 1.6.1
NetBSD NetBSD 1.6 beta
NetBSD NetBSD 1.6
NetBSD NetBSD Current
Mandriva Linux Mandrake 10.2 x86_64
Mandriva Linux Mandrake 10.2
Debian Linux 3.1 sparc
Debian Linux 3.1 s/390
Debian Linux 3.1 ppc
Debian Linux 3.1 mipsel
Debian Linux 3.1 mips
Debian Linux 3.1 m68k
Debian Linux 3.1 ia-64
Debian Linux 3.1 ia-32
Debian Linux 3.1 hppa
Debian Linux 3.1 arm
Debian Linux 3.1 amd64
Debian Linux 3.1 alpha
Debian Linux 3.1
Conectiva Linux 10.0
NTP NTPd 4.2 .0b

NTP NTPd 4.2 .0b

The ntpd daemon is prone to an insecure privileges vulnerability.

The application may be started with the effective permissions of a privileged user; if the application is compromised by some other means, this may allow an attacker to conduct further exploits.

The vendor has released an update to correct this vulnerability.

Please see the referenced advisories for more information.

