CVE-2016-7434 is a denial-of-service vulnerability in NTP (ntpd) prior to 4.2.8p9. The flaw is in the read_mru_list function, which processes MRU (Most Recently Used) list requests. A remote attacker can send a crafted mrulist query that triggers a crash of the ntpd process, resulting in denial of service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a proof-of-concept exploit for CVE-2016-7434, a remote pre-authentication denial of service vulnerability in ntpd. The main exploit file, 'ntpd-preauth-DoS.py', is a Python script that sends a specifically crafted UDP packet to a target host's ntpd service (default port 123). If the target is running a vulnerable version of ntpd (4.2.7p22 up to but not including 4.2.8p9, or 4.3.0 up to but not including 4.3.94), the malformed packet will cause a null pointer dereference, crashing the ntpd process and resulting in a denial of service. The repository also includes a README with usage instructions and references, and a detailed text file ('ntpd-preauth-DoS.txt') containing vulnerability details, proof-of-concept commands, and a valgrind crash report. No hardcoded IP addresses or domains are present; the exploit is generic and requires the user to specify the target host and port. The exploit is a straightforward POC and does not include advanced features or payload customization.
This repository provides a working denial-of-service (DoS) exploit for CVE-2016-7434, a vulnerability in ntpd (Network Time Protocol Daemon) versions 4.2.8p8 and earlier. The vulnerability is a null pointer dereference in the handling of 'mrulist' query requests, which can be triggered remotely if the target ntpd is configured to allow such queries. The repository includes both a Python script (exploit.py) and a Bash script (exploit.sh) that send a specially crafted UDP packet to the target's port 123, causing the ntpd process to crash. The exploit is operational and can be used to test vulnerable systems, including a provided Dockerfile and instructions for setting up a vulnerable test environment. The main attack vector is network-based, targeting UDP port 123. The exploit does not provide post-exploitation capabilities beyond denial of service. The repository also includes the full source code for ntp-4.2.8p8 for reference and testing.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.