PT-2015-3300 · Ntf+4 · Ntp+5

Aanchal Malhotra

+3

·

Published

2015-10-21

·

Updated

2024-06-15

·

CVE-2015-7705

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NTP versions 4.x before 4.2.8p4 NTP versions 4.3.x before 4.3.77
Description The rate limiting feature in NTP allows remote attackers to have unspecified impact via a large number of crafted requests. This issue exists due to insufficient input validation, which may allow a remote attacker to cause partial disruption of confidentiality, integrity, and availability of protected information by sending a large number of reverse requests.
Recommendations For NTP versions 4.x before 4.2.8p4, update to version 4.2.8p4 or later. For NTP versions 4.3.x before 4.3.77, update to version 4.3.77 or later.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2335
BDU:2017-02017
CVE-2015-7705
OPENSUSE-SU-2016_1329-1
OPENSUSE-SU-2024:10181-1
SUSE-SU-2015:2058-1
SUSE-SU-2016:1247-1
SUSE-SU-2016:1278-1
SUSE-SU-2016:1291-1
SUSE-SU-2016:1311-1
SUSE-SU-2016:1471-1
SUSE-SU-2016:1568-1
USN-2783-1

Affected Products

Alt Linux
Cisco Ios Xe
Cisco Nexus
Ntp
Suse
Ubuntu