Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7704

Опубликовано: 21 окт. 2015
Источник: redhat
CVSS2: 6.4
EPSS Средний

Описание

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.

It was discovered that ntpd as a client did not correctly check timestamps in Kiss-of-Death packets. A remote attacker could use this flaw to send a crafted Kiss-of-Death packet to an ntpd client that would increase the client's polling interval value, and effectively disable synchronization with the server.

Отчет

This issue did not affect the versions of ntp as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6.4, as they do not include support for KoD packets.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ntpNot affected
Red Hat Enterprise Linux Extended Update Support 6.4ntpNot affected
Red Hat Enterprise Linux 6ntpFixedRHSA-2015:193026.10.2015
Red Hat Enterprise Linux 6.5 Extended Update SupportntpFixedRHSA-2015:252026.11.2015
Red Hat Enterprise Linux 6.6 Extended Update SupportntpFixedRHSA-2015:252026.11.2015
Red Hat Enterprise Linux 7ntpFixedRHSA-2015:193026.10.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1271070ntp: disabling synchronization via crafted KoD packet

EPSS

Процентиль: 96%
0.22612
Средний

6.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.

CVSS3: 7.5
nvd
больше 8 лет назад

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.

CVSS3: 7.5
debian
больше 8 лет назад

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allo ...

CVSS3: 7.5
github
больше 3 лет назад

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.

oracle-oval
около 10 лет назад

ELSA-2015-1930: ntp security update (IMPORTANT)

EPSS

Процентиль: 96%
0.22612
Средний

6.4 Medium

CVSS2