Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-5146

Опубликовано: 24 авг. 2017
Источник: nvd
CVSS3: 5.3
CVSS2: 3.5
EPSS Низкий

Описание

ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:ntp:ntp:*:p2:*:*:*:*:*:*
Версия до 4.2.8 (включая)

EPSS

Процентиль: 85%
0.0236
Низкий

5.3 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 8 лет назад

ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.

redhat
больше 10 лет назад

ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.

CVSS3: 5.3
debian
больше 8 лет назад

ntpd in ntp before 4.2.8p3 with remote configuration enabled allows re ...

CVSS3: 5.3
github
больше 3 лет назад

ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.

EPSS

Процентиль: 85%
0.0236
Низкий

5.3 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-20