Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5196

Опубликовано: 25 авг. 2015
Источник: redhat
CVSS2: 4

Описание

It was found that NTP's :config command could be used to set the pidfile and driftfile paths without any restrictions. A remote attacker could use this flaw to overwrite a file on the file system with a file containing the pid of the ntpd process (immediately) or the current estimated drift of the system clock (in hourly intervals).

Меры по смягчению последствий

Disable remote runtime configuration with ntpq or ntpdc. In the default NTP configuration on Red Hat Enterprise Linux, runtime configuration with ntpq or ntpdc is limited to localhost.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ntpWill not fix
Red Hat Enterprise Linux 6ntpAffected
Red Hat Enterprise Linux 7ntpFixedRHSA-2016:258303.11.2016

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-73
https://bugzilla.redhat.com/show_bug.cgi?id=1254547ntp: config command can be used to set the pidfile and drift file paths

4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 10 лет назад

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7703. Reason: This candidate is a reservation duplicate of CVE-2015-7703. Notes: All CVE users should reference CVE-2015-7703 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

nvd
почти 10 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7703. Reason: This candidate is a reservation duplicate of CVE-2015-7703. Notes: All CVE users should reference CVE-2015-7703 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

oracle-oval
почти 9 лет назад

ELSA-2016-2583: ntp security and bug fix update (MODERATE)

4 Medium

CVSS2