Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-7851

Опубликовано: 28 янв. 2020
Источник: debian

Описание

Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ntpfixed1:4.2.8p4+dfsg-1package
ntpno-dsajessiepackage
ntpno-dsawheezypackage
ntpno-dsasqueezepackage

Примечания

  • http://support.ntp.org/bin/view/Main/SecurityNotice#October_2015_NTP_Security_Vulner

  • https://github.com/ntp-project/ntp/commit/184516e143ce4448ddb5b9876dd372008cc779f6

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.

redhat
больше 10 лет назад

Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.

CVSS3: 6.5
nvd
около 6 лет назад

Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.

github
больше 3 лет назад

Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.

suse-cvrf
около 10 лет назад

Security update for ntp