Community discussions

MikroTik App
 
User avatar
jp
Long time Member
Long time Member
Topic Author
Posts: 617
Joined: Wed Mar 02, 2005 5:06 am
Location: Maine
Contact:

NTP vulnerabilities

Sun Jan 18, 2015 3:24 pm

NTP vuln is pretty widespread with many vendors, but how each responds to it is what separates the men from the boys.

The 6.25 rc changelog says it fixes NTP vulnerabilities. Does that mean all previous versions have vulnerabilities? Please share more.

An ideal thing for MT to do would be say "this is a vulnerability, please work around with this firewall rule. It affects versions a,b,c... We're working on a software update."
 
User avatar
hossain2004a
Member Candidate
Member Candidate
Posts: 247
Joined: Mon Dec 22, 2014 7:34 pm
Location: Iran

Re: NTP vulnerabilities

Tue Jan 20, 2015 12:28 pm

I just didn't update....

hope there would be no problem with that :D
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 27129
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: NTP vulnerabilities

Tue Jan 20, 2015 1:14 pm

Fix was released in December: http://forum.mikrotik.com/viewtopic.php ... 96#p461196

RouterOS all versions are only affected by the buffer overflow problem, but if you have default config, your public interface already has firewall.