PT-2016-3111 · Nts+1 · Ntp+1

Adam Mariš

·

Publicado

2016-01-22

·

Atualizado

2017-04-20

·

CVE-2016-0727

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ntp versions prior to 1:4.2.6.p3+dfsg-1ubuntu3.11 ntp versions prior to 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 ntp versions prior to 1:4.2.8p4+dfsg-3ubuntu5.3
Description The issue is related to the crontab script in the ntp package, which allows local users with access to the ntp account to write to arbitrary files and gain privileges via vectors involving statistics directory cleanup. This is due to insufficient access control.
Recommendations For versions prior to 1:4.2.6.p3+dfsg-1ubuntu3.11, update to version 1:4.2.6.p3+dfsg-1ubuntu3.11 or later. For versions prior to 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10, update to version 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 or later. For versions prior to 1:4.2.8p4+dfsg-3ubuntu5.3, update to version 1:4.2.8p4+dfsg-3ubuntu5.3 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-01267
CVE-2016-0727
USN-3096-1

Produtos afetados

Ubuntu
Ntp