Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-7976

Опубликовано: 30 янв. 2017
Источник: debian
EPSS Низкий

Описание

The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ntpfixed1:4.2.8p7+dfsg-1package
ntpno-dsajessiepackage
ntpno-dsawheezypackage

Примечания

  • http://support.ntp.org/bin/view/Main/SecurityNotice#January_2016_NTP_4_2_8p6_Securit

  • http://support.ntp.org/bin/view/Main/NtpBug2938

  • https://github.com/ntp-project/ntp/commit/3680c2e4d5f88905ce062c7b43305d610a2c9796

  • https://github.com/ntp-project/ntp/commit/7fe04606062ed674db3b9553d32dedad29504d61

EPSS

Процентиль: 87%
0.03168
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 9 лет назад

The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.

redhat
около 10 лет назад

The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.

CVSS3: 4.3
nvd
около 9 лет назад

The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.

CVSS3: 4.3
github
больше 3 лет назад

The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.

suse-cvrf
больше 9 лет назад

Security update for ntp

EPSS

Процентиль: 87%
0.03168
Низкий