7.5
CVE-2015-7704
- EPSS 10.95%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Netapp ≫ Oncommand Performance Manager Version -
Netapp ≫ Oncommand Unified Manager Version - SwPlatform clustered_data_ontap
Netapp ≫ Clustered Data Ontap Version -
Netapp ≫ Data Ontap Version - SwPlatform 7-mode
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 6.5
Redhat ≫ Enterprise Linux Server Aus Version 6.6
Redhat ≫ Enterprise Linux Server Aus Version 7.3
Redhat ≫ Enterprise Linux Server Aus Version 7.4
Redhat ≫ Enterprise Linux Server Aus Version 7.6
Redhat ≫ Enterprise Linux Server Aus Version 7.7
Redhat ≫ Enterprise Linux Server Eus Version 6.5
Redhat ≫ Enterprise Linux Server Eus Version 6.6
Redhat ≫ Enterprise Linux Server Eus Version 6.7
Redhat ≫ Enterprise Linux Server Eus Version 7.1
Redhat ≫ Enterprise Linux Server Eus Version 7.3
Redhat ≫ Enterprise Linux Server Eus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.5
Redhat ≫ Enterprise Linux Server Eus Version 7.6
Redhat ≫ Enterprise Linux Server Eus Version 7.7
Redhat ≫ Enterprise Linux Server Tus Version 6.5
Redhat ≫ Enterprise Linux Server Tus Version 6.6
Redhat ≫ Enterprise Linux Server Tus Version 7.3
Redhat ≫ Enterprise Linux Server Tus Version 7.6
Redhat ≫ Enterprise Linux Server Tus Version 7.7
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Mcafee ≫ Enterprise Security Manager Version < 10.4.0
Mcafee ≫ Enterprise Security Manager Version >= 11.0.0 < 11.2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 10.95% | 0.953 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.debian.org/security/2015/dsa-3388
https://security.gentoo.org/glsa/201607-15
http://www.securitytracker.com/id/1033951
https://security.netapp.com/advisory/ntap-20171004-0001/
https://security.netapp.com/advisory/ntap-20171004-0002/
https://www.kb.cert.org/vuls/id/718152
https://support.citrix.com/article/CTX220112
http://rhn.redhat.com/errata/RHSA-2015-1930.html
https://www.cs.bu.edu/~goldbe/NTPattack.html
http://bugs.ntp.org/show_bug.cgi?id=2901
http://rhn.redhat.com/errata/RHSA-2015-2520.html
http://support.ntp.org/bin/view/Main/NtpBug2901
http://support.ntp.org/bin/view/Main/SecurityNotice#October_2015_NTP_4_2_8p4_Securit
http://www.securityfocus.com/bid/77280
https://bugzilla.redhat.com/show_bug.cgi?id=1271070
https://eprint.iacr.org/2015/1020.pdf
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05270839
https://kc.mcafee.com/corporate/index?page=content&id=SB10284
https://www.arista.com/en/support/advisories-notices/security-advisories/1212-security-advisory-0016