PT-2015-6797 · Nts+5 · Ntp+5

Martin Prpič

·

Published

2014-12-24

·

Updated

2023-02-13

·

CVE-2015-5194

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ntp versions prior to 4.2.7p42
Description The issue allows remote attackers to cause a denial of service, resulting in the ntpd crash, via crafted logconfig commands. This is due to an uninitialized variable when processing malformed logconfig configuration commands.
Recommendations For versions prior to 4.2.7p42, update to version 4.2.7p42 or later to resolve the issue. As a temporary workaround, consider restricting access to the logconfig command to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2486
CESA-2016_0780
CESA-2016_2583
CVE-2015-5194
DLA-335-1
DSA-3388-1
MGASA-2015-0348
RHSA-2016:0780
RHSA-2016:2583
RHSA-2016_0780
RHSA-2016_2583
SUSE-SU-2016:1311-1
SUSE-SU-2016_1311-1
USN-2783-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Ntp