7.5

CVE-2015-5194

The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 21
Fedoraproject ≫ Fedora Version 22
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp2
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp3
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwEdition ltss
Suse ≫ Manager Version 2.1
Suse ≫ Manager Proxy Version 2.1
Suse ≫ Openstack Cloud Version 5
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 15.04
Canonical ≫ Ubuntu Linux Version 15.10
Ntp ≫ Ntp Update p40 Version <= 4.2.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.54% 0.918
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
http://www.debian.org/security/2015/dsa-3388
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2583.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0780.html
Third Party Advisory
http://bk1.ntp.org/ntp-dev/?PAGE=patch&REV=4c4fc141LwvcoGp-lLGhkAFp3ZvtrA
Patch
Vendor Advisory
Issue Tracking
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170926.html
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169167.html
Third Party Advisory
http://www.openwall.com/lists/oss-security/2015/08/25/3
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/76475
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-2783-1
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1254542
Patch
Issue Tracking
https://github.com/ntp-project/ntp/commit/553f2fa65865c31c5e3c48812cfd46176cffdd27
Patch
Third Party Advisory
Issue Tracking
https://www-01.ibm.com/support/docview.wss?uid=isg3T1024157
Third Party Advisory
https://www-01.ibm.com/support/docview.wss?uid=swg21985122
Third Party Advisory
https://www-01.ibm.com/support/docview.wss?uid=swg21986956
Third Party Advisory
https://www-01.ibm.com/support/docview.wss?uid=swg21988706
Third Party Advisory
https://www-01.ibm.com/support/docview.wss?uid=swg21989542
Third Party Advisory