6.5

CVE-2015-7702

The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash).  NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ntp ≫ Ntp Version >= 4.2.0 < 4.2.8
Ntp ≫ Ntp Version >= 4.3.0 < 4.3.77
Ntp ≫ Ntp Version 4.2.8 Update -
Ntp ≫ Ntp Version 4.2.8 Update p1
Ntp ≫ Ntp Version 4.2.8 Update p1-beta1
Ntp ≫ Ntp Version 4.2.8 Update p1-beta2
Ntp ≫ Ntp Version 4.2.8 Update p1-beta3
Ntp ≫ Ntp Version 4.2.8 Update p1-beta4
Ntp ≫ Ntp Version 4.2.8 Update p1-beta5
Ntp ≫ Ntp Version 4.2.8 Update p1-rc1
Ntp ≫ Ntp Version 4.2.8 Update p1-rc2
Ntp ≫ Ntp Version 4.2.8 Update p2
Ntp ≫ Ntp Version 4.2.8 Update p2-rc1
Ntp ≫ Ntp Version 4.2.8 Update p2-rc2
Ntp ≫ Ntp Version 4.2.8 Update p2-rc3
Ntp ≫ Ntp Version 4.2.8 Update p3
Ntp ≫ Ntp Version 4.2.8 Update p3-rc1
Ntp ≫ Ntp Version 4.2.8 Update p3-rc2
Ntp ≫ Ntp Version 4.2.8 Update p3-rc3
Oracle ≫ Linux Version 6 Update -
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Netapp ≫ Oncommand Unified Manager Version - SwPlatform clustered_data_ontap
Netapp ≫ Data Ontap Version - SwPlatform 7-mode
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.21% 0.914
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
Third Party Advisory
http://www.debian.org/security/2015/dsa-3388
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2583.html
Third Party Advisory
https://security.gentoo.org/glsa/201607-15
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033951
Third Party Advisory
VDB Entry
https://security.netapp.com/advisory/ntap-20171004-0001/
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0780.html
Third Party Advisory
http://support.ntp.org/bin/view/Main/NtpBug2899
Vendor Advisory
http://www.securityfocus.com/bid/77286
Third Party Advisory
VDB Entry