7.5

CVE-2015-3405

ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ntp ≫ Ntp Version 4.2.8 Update p1
Ntp ≫ Ntp Version 4.2.8 Update p2
Ntp ≫ Ntp Version 4.2.8 Update p2-rc1
Ntp ≫ Ntp Version 4.3.0
Ntp ≫ Ntp Version 4.3.1
Ntp ≫ Ntp Version 4.3.2
Ntp ≫ Ntp Version 4.3.3
Ntp ≫ Ntp Version 4.3.4
Ntp ≫ Ntp Version 4.3.5
Ntp ≫ Ntp Version 4.3.6
Ntp ≫ Ntp Version 4.3.7
Ntp ≫ Ntp Version 4.3.8
Ntp ≫ Ntp Version 4.3.9
Ntp ≫ Ntp Version 4.3.10
Ntp ≫ Ntp Version 4.3.11
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Opensuse ≫ Suse Linux Enterprise Server Version 11.0 Update sp3
Opensuse Project ≫ Suse Linux Enterprise Desktop Version 11.0 Update sp3
Suse ≫ Suse Linux Enterprise Server Version 11.0 Update sp3 SwPlatform vmware
Fedoraproject ≫ Fedora Version 21
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.29% 0.915
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-331 Insufficient Entropy

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://rhn.redhat.com/errata/RHSA-2015-1459.html
Third Party Advisory
VDB Entry
http://www.debian.org/security/2015/dsa-3223
Third Party Advisory
http://www.debian.org/security/2015/dsa-3388
Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03886en_us
http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=55199296N2gFqH1Hm5GOnhrk9Ypygg
Third Party Advisory
Vendor Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156248.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00000.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2231.html
Third Party Advisory
VDB Entry
http://www.openwall.com/lists/oss-security/2015/04/23/14
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/74045
Third Party Advisory
VDB Entry
https://bugs.ntp.org/show_bug.cgi?id=2797
Third Party Advisory
Vendor Advisory
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1210324
Patch
Third Party Advisory
VDB Entry
Issue Tracking