7.5

CVE-2015-7704

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ntp ≫ Ntp Version >= 4.2.0 < 4.2.8
Ntp ≫ Ntp Version >= 4.3.0 < 4.3.77
Ntp ≫ Ntp Version 4.2.8 Update -
Ntp ≫ Ntp Version 4.2.8 Update p1
Ntp ≫ Ntp Version 4.2.8 Update p1-beta1
Ntp ≫ Ntp Version 4.2.8 Update p1-beta2
Ntp ≫ Ntp Version 4.2.8 Update p1-beta3
Ntp ≫ Ntp Version 4.2.8 Update p1-beta4
Ntp ≫ Ntp Version 4.2.8 Update p1-beta5
Ntp ≫ Ntp Version 4.2.8 Update p1-rc1
Ntp ≫ Ntp Version 4.2.8 Update p1-rc2
Ntp ≫ Ntp Version 4.2.8 Update p2
Ntp ≫ Ntp Version 4.2.8 Update p2-rc1
Ntp ≫ Ntp Version 4.2.8 Update p2-rc2
Ntp ≫ Ntp Version 4.2.8 Update p2-rc3
Ntp ≫ Ntp Version 4.2.8 Update p3
Ntp ≫ Ntp Version 4.2.8 Update p3-rc1
Ntp ≫ Ntp Version 4.2.8 Update p3-rc2
Ntp ≫ Ntp Version 4.2.8 Update p3-rc3
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Netapp ≫ Oncommand Unified Manager Version - SwPlatform clustered_data_ontap
Netapp ≫ Data Ontap Version - SwPlatform 7-mode
Mcafee ≫ Enterprise Security Manager Version < 10.4.0
Mcafee ≫ Enterprise Security Manager Version >= 11.0.0 < 11.2.0
Citrix ≫ Xenserver Version 6.0.2
Citrix ≫ Xenserver Version 6.2.0 Update -
Citrix ≫ Xenserver Version 6.5 Update -
Citrix ≫ Xenserver Version 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.95% 0.953
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
Third Party Advisory
http://www.debian.org/security/2015/dsa-3388
Third Party Advisory
https://security.gentoo.org/glsa/201607-15
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033951
Third Party Advisory
VDB Entry
https://security.netapp.com/advisory/ntap-20171004-0001/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20171004-0002/
Third Party Advisory
https://www.kb.cert.org/vuls/id/718152
Third Party Advisory
US Government Resource
https://support.citrix.com/article/CTX220112
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-1930.html
Third Party Advisory
https://www.cs.bu.edu/~goldbe/NTPattack.html
Third Party Advisory
http://bugs.ntp.org/show_bug.cgi?id=2901
Vendor Advisory
Issue Tracking
http://rhn.redhat.com/errata/RHSA-2015-2520.html
Third Party Advisory
http://support.ntp.org/bin/view/Main/NtpBug2901
Vendor Advisory
http://support.ntp.org/bin/view/Main/SecurityNotice#October_2015_NTP_4_2_8p4_Securit
Vendor Advisory
Release Notes
http://www.securityfocus.com/bid/77280
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1271070
Third Party Advisory
VDB Entry
Issue Tracking
https://eprint.iacr.org/2015/1020.pdf
Third Party Advisory
Technical Description
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05270839
Third Party Advisory
VDB Entry
https://kc.mcafee.com/corporate/index?page=content&id=SB10284
Third Party Advisory
https://www.arista.com/en/support/advisories-notices/security-advisories/1212-security-advisory-0016