7.5
CVE-2015-3405
- EPSS 5.29%
- Veröffentlicht 09.08.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Opensuse ≫ Suse Linux Enterprise Server Version 11.0 Update sp3
Opensuse Project ≫ Suse Linux Enterprise Desktop Version 11.0 Update sp3
Suse ≫ Suse Linux Enterprise Server Version 11.0 Update sp3 SwPlatform vmware
Fedoraproject ≫ Fedora Version 21
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 6.0
Redhat ≫ Enterprise Linux For Power Big Endian Version 6.0
Redhat ≫ Enterprise Linux For Scientific Computing Version 6.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server From Rhui 6 Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.29% | 0.915 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-331 Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://rhn.redhat.com/errata/RHSA-2015-1459.html
http://www.debian.org/security/2015/dsa-3223
http://www.debian.org/security/2015/dsa-3388
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03886en_us
http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=55199296N2gFqH1Hm5GOnhrk9Ypygg
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156248.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00000.html
http://rhn.redhat.com/errata/RHSA-2015-2231.html
http://www.openwall.com/lists/oss-security/2015/04/23/14
http://www.securityfocus.com/bid/74045
https://bugs.ntp.org/show_bug.cgi?id=2797
https://bugzilla.redhat.com/show_bug.cgi?id=1210324