4.9

CVE-2020-15025

ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ntp ≫ Ntp Version >= 4.3.97 < 4.3.101
Ntp ≫ Ntp Version 4.2.8 Update p11
Ntp ≫ Ntp Version 4.2.8 Update p12
Ntp ≫ Ntp Version 4.2.8 Update p13
Ntp ≫ Ntp Version 4.2.8 Update p14
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Netapp ≫ Cloud Backup Version -
Netapp ≫ 8300 Firmware Version -
   Netapp ≫ 8300 Version -
Netapp ≫ 8700 Firmware Version -
   Netapp ≫ 8700 Version -
Netapp ≫ A400 Firmware Version -
   Netapp ≫ A400 Version -
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H300e Firmware Version -
   Netapp ≫ H300e Version -
Netapp ≫ H500e Firmware Version -
   Netapp ≫ H500e Version -
Netapp ≫ H700e Firmware Version -
   Netapp ≫ H700e Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.36% 0.871
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
MITRE 4.4 0.7 3.6
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://www.oracle.com/security-alerts/cpujan2021.html
Patch
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00044.html
Third Party Advisory
Mailing List
https://security.gentoo.org/glsa/202007-12
Third Party Advisory
https://bugs.gentoo.org/729458
Third Party Advisory
Issue Tracking
https://security.netapp.com/advisory/ntap-20200702-0002/
Third Party Advisory
https://support.ntp.org/bin/view/Main/NtpBug3661
Vendor Advisory
https://support.ntp.org/bin/view/Main/SecurityNotice#June_2020_ntp_4_2_8p15_NTP_Relea
Vendor Advisory
Release Notes