PT-2015-7689 · Ntp+7 · Ntpd+8
Stephen Gray
·
Published
2015-12-31
·
Updated
2024-06-15
·
CVE-2015-7977
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ntpd versions 4.2.8p5 and earlier, 4.3.x prior to 4.3.90
Description
The issue allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference, via a ntpdc reslist command.
Recommendations
For versions 4.2.8p5 and earlier, update to version 4.2.8p6 or later.
For versions 4.3.x prior to 4.3.90, update to version 4.3.90 or later.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Cisco Ios Xr
Cisco Nexus
Freebsd
Red Hat
Suse
Ubuntu
Ntpd