Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7433

Опубликовано: 13 янв. 2017
Источник: debian
EPSS Средний

Описание

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ntpfixed1:4.2.8p9+dfsg-1package
ntpnot-affectedjessiepackage
ntpnot-affectedwheezypackage

Примечания

  • http://support.ntp.org/bin/view/Main/NtpBug3067

  • Although the CVE is only for the issue introduced by the fix for

  • http://bugs.ntp.org/show_bug.cgi?id=2085, he root-distance calculation

  • itself in general is incorrect in all version of ntp-4 until ntp-4.2.8p9

EPSS

Процентиль: 97%
0.36227
Средний

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 9 лет назад

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

CVSS3: 2.9
redhat
почти 9 лет назад

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

CVSS3: 5.3
nvd
почти 9 лет назад

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

CVSS3: 5.3
github
больше 3 лет назад

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

oracle-oval
почти 9 лет назад

ELSA-2017-0252: ntp security update (MODERATE)

EPSS

Процентиль: 97%
0.36227
Средний