NTP.org has published a security advisory for six vulnerabilities resolved in ntpd (NTP daemon) that have been assigned four CVE IDs. In the worst case, some of these issues may allow remote unauthenticated attackers to execute code with the privileges of ntpd or cause a denial of service condition.
Vulnerable Products:
[edit system ntp]
tar -zxf glibc-ntp-hotpatch-vz.tgz
cd glibc-ntp-hotpatch-v1
sh patchme.sh
IMPORTANT
sh fixupgrade.sh
Junos OS: Standard security best current practices (control plane firewall filters, edge filtering, access lists, etc.) will protect against any remote malicious attacks against NTP. Customers who have already applied the workaround described in JSA10613 [juniper.net] are already protected against any remote exploitation of these vulnerabilities. Refer to the Workaround section of JSA10613 [juniper.net] for specific applicable mitigation techniques. NSM: Turning off NTP daemon by unchecking the "Automatically Sync Time" option (under Time Server settings in Web UI) should completely mitigate these issues. vGW: Disable NTP services or limit access to NTP from trusted hosts.
2015-01-05: Initial release. 2015-01-08: Confirmed that CVE-2014-9294 and CVE-2014-9296 may also apply to Junos. 2015-01-15: Explicitly stated that JUNOSe is not vulnerable. 2015-01-21: Added vGW Series. 2015-02-03: Added explicit statement about CVE-2014-9293 not affecting Junos. 2015-02-24: Added Junos Space. 2015-02-24: Added fixed releases for Junos OS. 2015-02-26: Added Junos Space hot-patch info. 2015-02-27: Removed End-of-Engineering release 11.4 from Junos OS fixed release list. 2015-03-10: Confirmed that only CVE-2014-9295 affects Junos. 2015-03-23: Clarified Junos Space patch instructions. 2015-09-03: Added references to CVE-2014-9297 (formerly known as "NTP Bug 2671") and CVE-2014-9298 (formerly known as "NTP Bug 2672"). 2015-12-09: Added NSM patch instructions.