Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffj6-rf7h-c479

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.

EPSS

Процентиль: 93%
0.09651
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 10 лет назад

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.

redhat
почти 11 лет назад

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.

nvd
около 10 лет назад

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.

debian
около 10 лет назад

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before ...

oracle-oval
почти 10 лет назад

ELSA-2015-2231: ntp security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 93%
0.09651
Низкий

Дефекты

CWE-20