PT-2015-6797 · Nts+5 · Ntp+5

·

CVE-2015-5194

·

Publicado

2014-12-24

·

Atualizado

2023-02-13

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ntp versions prior to 4.2.7p42
Description The issue allows remote attackers to cause a denial of service, resulting in the ntpd crash, via crafted logconfig commands. This is due to an uninitialized variable when processing malformed logconfig configuration commands.
Recommendations For versions prior to 4.2.7p42, update to version 4.2.7p42 or later to resolve the issue. As a temporary workaround, consider restricting access to the logconfig command to minimize the risk of exploitation.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2486
CESA-2016_0780
CESA-2016_2583
CVE-2015-5194
DLA-335-1
DSA-3388-1
MGASA-2015-0348
RHSA-2016:0780
RHSA-2016:2583
RHSA-2016_0780
RHSA-2016_2583
SUSE-SU-2016:1311-1
SUSE-SU-2016_1311-1
USN-2783-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Ntp