4.6

CVE-2005-2496

The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dave MillsNtpd Version <= 4.2.0.a.2004-06-17_4.fc3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.353
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/16602
Vendor Advisory
http://secunia.com/advisories/21464
http://securitytracker.com/id?1016679
http://www.debian.org/security/2005/dsa-801
http://www.mandriva.com/security/advisories?name=MDKSA-2005:156
http://www.osvdb.org/19055
http://www.redhat.com/support/errata/RHSA-2006-0393.html
http://www.securityfocus.com/bid/14673
http://www.securityspace.com/smysecure/catid.html?id=55155
Vendor Advisory
http://www.vupen.com/english/advisories/2005/1561
https://exchange.xforce.ibmcloud.com/vulnerabilities/22035
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9669