Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7851

Опубликовано: 21 окт. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.

Отчет

This issue did not affect the versions of ntp as shipped with Red Hat Enterprise Linux 5, 6, and 7. This issue only affected OpenVMS operating systems, which use characters other than "/" and "" for directory separation, allowing exploitation of this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ntpNot affected
Red Hat Enterprise Linux 6ntpNot affected
Red Hat Enterprise Linux 7ntpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1274260ntp: saveconfig directory traversal vulnerability

EPSS

Процентиль: 67%
0.00532
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.

CVSS3: 6.5
nvd
около 6 лет назад

Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.

CVSS3: 6.5
debian
около 6 лет назад

Directory traversal vulnerability in the save_config function in ntpd ...

github
больше 3 лет назад

Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.

suse-cvrf
около 10 лет назад

Security update for ntp

EPSS

Процентиль: 67%
0.00532
Низкий

4.3 Medium

CVSS2