7.5
CVE-2015-5300
- EPSS 9.13%
- Veröffentlicht 21.07.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 21
Fedoraproject ≫ Fedora Version 22
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp2
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp3
Suse ≫ Linux Enterprise Debuginfo Version 11 Update sp4
Suse ≫ Linux Enterprise Desktop Version 12
Suse ≫ Linux Enterprise Desktop Version 12 Update sp1
Suse ≫ Linux Enterprise Server Version 10 Update sp4 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp2 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp3 SwEdition ltss
Suse ≫ Linux Enterprise Server Version 11 Update sp4
Suse ≫ Linux Enterprise Server Version 12 Update sp1
Suse ≫ Linux Enterprise Software Development Kit Version 12
Suse ≫ Linux Enterprise Software Development Kit Version 12 Update sp1
Suse ≫ Manager Proxy Version 2.1
Suse ≫ Openstack Cloud Version 5
Suse ≫ Suse Linux Enterprise Server Version 12
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Version 6.0
Redhat ≫ Enterprise Linux Hpc Node Version 7.0
Redhat ≫ Enterprise Linux Hpc Node Eus Version 7.1
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Eus Version 6.7.z
Redhat ≫ Enterprise Linux Server Eus Version 7.1
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 15.04
Canonical ≫ Ubuntu Linux Version 15.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.13% | 0.947 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
http://www.debian.org/security/2015/dsa-3388
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.html
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.html
https://security.netapp.com/advisory/ntap-20171004-0001/
http://lists.opensuse.org/opensuse-updates/2016-05/msg00114.html
https://support.citrix.com/article/CTX220112
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00059.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00060.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00020.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00038.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.html
https://bto.bluecoat.com/security-advisory/sa113
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177507.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170926.html
http://www.ubuntu.com/usn/USN-2783-1
http://aix.software.ibm.com/aix/efixes/security/ntp_advisory5.asc
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170684.html
http://rhn.redhat.com/errata/RHSA-2015-1930.html
http://seclists.org/bugtraq/2016/Feb/164
http://support.ntp.org/bin/view/Main/NtpBug2956
http://support.ntp.org/bin/view/Main/SecurityNotice#January_2016_NTP_4_2_8p5_Securit
http://www.securityfocus.com/bid/77312
http://www.securitytracker.com/id/1034670
https://bugzilla.redhat.com/show_bug.cgi?id=1271076
https://ics-cert.us-cert.gov/advisories/ICSA-15-356-01
https://www-01.ibm.com/support/docview.wss?uid=isg3T1023885
https://www-01.ibm.com/support/docview.wss?uid=isg3T1024073
https://www-01.ibm.com/support/docview.wss?uid=nas8N1021264
https://www-01.ibm.com/support/docview.wss?uid=ssg1S1005821
https://www-01.ibm.com/support/docview.wss?uid=swg21979393
https://www-01.ibm.com/support/docview.wss?uid=swg21980676
https://www-01.ibm.com/support/docview.wss?uid=swg21983501
https://www-01.ibm.com/support/docview.wss?uid=swg21983506
https://www.cs.bu.edu/~goldbe/NTPattack.html
https://www.freebsd.org/security/advisories/FreeBSD-SA-16:02.ntp.asc
https://www.ibm.com/support/home/docdisplay?lndocid=migr-5099428
https://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
https://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html