Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-15025

Опубликовано: 24 июн. 2020
Источник: debian
EPSS Низкий

Описание

ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ntpfixed1:4.2.8p15-1package
ntpno-dsabusterpackage
ntpnot-affectedstretchpackage
ntpnot-affectedjessiepackage
ntpsecnot-affectedpackage

Примечания

  • https://support.ntp.org/bin/view/Main/NtpBug3661

  • https://support.ntp.org/bin/view/Main/SecurityNotice#June_2020_ntp_4_2_8p15_NTP_Relea

  • https://bugs.ntp.org/show_bug.cgi?id=3661

  • http://bk.ntp.org/ntp-stable/?PAGE=patch&REV=5e84aa07N2NcL4sE_0dW35Tizc74SA

EPSS

Процентиль: 83%
0.02005
Низкий

Связанные уязвимости

CVSS3: 4.4
ubuntu
почти 5 лет назад

ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.

CVSS3: 4.4
redhat
почти 5 лет назад

ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.

CVSS3: 4.4
nvd
почти 5 лет назад

ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.

CVSS3: 4.9
github
около 3 лет назад

ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.

CVSS3: 4.9
fstec
почти 5 лет назад

Уязвимость демона ntpd реализации протокола синхронизации времени NTP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 83%
0.02005
Низкий