Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-7426

Опубликовано: 13 янв. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 4.3
EPSS Средний

Описание

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*
Версия от 4.2.6 (включая) до 4.2.8 (исключая)
cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*
Версия от 4.3.0 (включая) до 4.3.94 (исключая)
cpe:2.3:a:ntp:ntp:4.2.5:p203:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p204:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p205:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p206:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p207:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p208:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p209:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p210:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p211:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p212:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p213:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p214:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p215:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p216:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p217:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p218:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p219:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p220:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p221:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p222:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p223:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p224:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p225:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p226:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p227:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p228:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p229:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p230:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p231_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p232_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p233_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p234_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p235_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p236_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p237_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p238_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p239_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p240_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p241_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p242_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p243_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p244_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p245_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p246_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p247_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p248_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p249_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p250_rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:-:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-beta1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-beta2:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-beta3:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-beta4:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-beta5:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-rc2:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p2:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p2-rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p2-rc2:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p2-rc3:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p3:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p3-rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p3-rc2:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p3-rc3:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p4:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p5:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p6:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p7:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p8:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.7:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:a:hpe:hpux-ntp:*:*:*:*:*:*:*:*
Версия от b.11.31 (включая) до c.4.2.8.2.0 (исключая)

EPSS

Процентиль: 97%
0.38912
Средний

7.5 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

CVSS3: 5.9
redhat
почти 9 лет назад

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

CVSS3: 7.5
debian
почти 9 лет назад

NTP before 4.2.8p9 rate limits responses received from the configured ...

CVSS3: 7.5
github
больше 3 лет назад

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

oracle-oval
почти 9 лет назад

ELSA-2017-0252: ntp security update (MODERATE)

EPSS

Процентиль: 97%
0.38912
Средний

7.5 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-400
Уязвимость CVE-2016-7426