5.9

CVE-2015-7977

ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NtpNtp Version <= 4.2.8
NtpNtp Version >= 4.3.0 < 4.3.90
NtpNtp Version4.2.8 Update-
NtpNtp Version4.2.8 Updatep1
NtpNtp Version4.2.8 Updatep1-beta1
NtpNtp Version4.2.8 Updatep1-beta2
NtpNtp Version4.2.8 Updatep1-beta3
NtpNtp Version4.2.8 Updatep1-beta4
NtpNtp Version4.2.8 Updatep1-beta5
NtpNtp Version4.2.8 Updatep1-rc1
NtpNtp Version4.2.8 Updatep1-rc2
NtpNtp Version4.2.8 Updatep2
NtpNtp Version4.2.8 Updatep2-rc1
NtpNtp Version4.2.8 Updatep2-rc2
NtpNtp Version4.2.8 Updatep2-rc3
NtpNtp Version4.2.8 Updatep3
NtpNtp Version4.2.8 Updatep3-rc1
NtpNtp Version4.2.8 Updatep3-rc2
NtpNtp Version4.2.8 Updatep3-rc3
NtpNtp Version4.2.8 Updatep4
NtpNtp Version4.2.8 Updatep5
OracleLinux Version6 Update-
SiemensTim 4r-ie Dnp3 Firmware Version-
   SiemensTim 4r-ie Dnp3 Version-
NetappOncommand Balance Version-
FreebsdFreebsd Version9.3 Update-
FreebsdFreebsd Version9.3 Updatep1
FreebsdFreebsd Version9.3 Updatep10
FreebsdFreebsd Version9.3 Updatep12
FreebsdFreebsd Version9.3 Updatep13
FreebsdFreebsd Version9.3 Updatep16
FreebsdFreebsd Version9.3 Updatep19
FreebsdFreebsd Version9.3 Updatep2
FreebsdFreebsd Version9.3 Updatep20
FreebsdFreebsd Version9.3 Updatep21
FreebsdFreebsd Version9.3 Updatep22
FreebsdFreebsd Version9.3 Updatep23
FreebsdFreebsd Version9.3 Updatep24
FreebsdFreebsd Version9.3 Updatep25
FreebsdFreebsd Version9.3 Updatep28
FreebsdFreebsd Version9.3 Updatep3
FreebsdFreebsd Version9.3 Updatep30
FreebsdFreebsd Version9.3 Updatep31
FreebsdFreebsd Version9.3 Updatep32
FreebsdFreebsd Version9.3 Updatep33
FreebsdFreebsd Version9.3 Updatep34
FreebsdFreebsd Version9.3 Updatep5
FreebsdFreebsd Version9.3 Updatep6
FreebsdFreebsd Version9.3 Updatep7
FreebsdFreebsd Version9.3 Updatep8
FreebsdFreebsd Version9.3 Updatep9
FreebsdFreebsd Version10.1 Update-
FreebsdFreebsd Version10.1 Updatep1
FreebsdFreebsd Version10.1 Updatep10
FreebsdFreebsd Version10.1 Updatep12
FreebsdFreebsd Version10.1 Updatep15
FreebsdFreebsd Version10.1 Updatep16
FreebsdFreebsd Version10.1 Updatep17
FreebsdFreebsd Version10.1 Updatep18
FreebsdFreebsd Version10.1 Updatep19
FreebsdFreebsd Version10.1 Updatep2
FreebsdFreebsd Version10.1 Updatep22
FreebsdFreebsd Version10.1 Updatep24
FreebsdFreebsd Version10.1 Updatep25
FreebsdFreebsd Version10.1 Updatep26
FreebsdFreebsd Version10.1 Updatep27
FreebsdFreebsd Version10.1 Updatep3
FreebsdFreebsd Version10.1 Updatep4
FreebsdFreebsd Version10.1 Updatep5
FreebsdFreebsd Version10.1 Updatep6
FreebsdFreebsd Version10.1 Updatep7
FreebsdFreebsd Version10.1 Updatep8
FreebsdFreebsd Version10.1 Updatep9
FreebsdFreebsd Version10.2 Update-
FreebsdFreebsd Version10.2 Updatep1
FreebsdFreebsd Version10.2 Updatep10
FreebsdFreebsd Version10.2 Updatep2
FreebsdFreebsd Version10.2 Updatep5
FreebsdFreebsd Version10.2 Updatep7
FreebsdFreebsd Version10.2 Updatep8
FreebsdFreebsd Version10.2 Updatep9
FedoraprojectFedora Version22
FedoraprojectFedora Version23
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
CanonicalUbuntu Linux Version12.04 SwEdition-
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionlts
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.71% 0.926
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

http://www.securitytracker.com/id/1034782
Third Party Advisory
VDB Entry
https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11
Third Party Advisory
US Government Resource
https://www.kb.cert.org/vuls/id/718152
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/81815
Third Party Advisory
VDB Entry