PT-2015-3299 · Ntt+5 · Ntp+6
Martin Prpič
·
Publicado
2015-10-21
·
Atualizado
2024-06-15
·
CVE-2015-7853
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NTP versions 4.2.x through 4.2.8p3
NTP versions 4.3.x through 4.3.76
Description
The issue is related to the
datalen parameter in the refclock driver, which allows remote attackers to execute arbitrary code or cause a denial of service via a negative input value. This is due to a buffer overflow in memory.Recommendations
For NTP versions 4.2.x through 4.2.8p3, update to version 4.2.8p4 or later.
For NTP versions 4.3.x through 4.3.76, update to version 4.3.77 or later.
As a temporary workaround, consider restricting the use of the
datalen parameter in the refclock driver until a patch is available.Exploit
Correção
RCE
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Cisco Ios Xe
Cisco Nexus
Ibm Aix
Ntp
Suse
Ubuntu