PT-2015-3299 · Ntt+5 · Ntp+6
Martin Prpič
·
Published
2015-10-21
·
Updated
2024-06-15
·
CVE-2015-7853
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NTP versions 4.2.x through 4.2.8p3
NTP versions 4.3.x through 4.3.76
Description
The issue is related to the
datalen parameter in the refclock driver, which allows remote attackers to execute arbitrary code or cause a denial of service via a negative input value. This is due to a buffer overflow in memory.Recommendations
For NTP versions 4.2.x through 4.2.8p3, update to version 4.2.8p4 or later.
For NTP versions 4.3.x through 4.3.76, update to version 4.3.77 or later.
As a temporary workaround, consider restricting the use of the
datalen parameter in the refclock driver until a patch is available.Exploit
Fix
RCE
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Cisco Ios Xe
Cisco Nexus
Ibm Aix
Ntp
Suse
Ubuntu