Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8138

Опубликовано: 20 янв. 2016
Источник: redhat
CVSS2: 6.4
EPSS Низкий

Описание

NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packet with an origin timestamp set to zero.

It was discovered that ntpd as a client did not correctly check the originate timestamp in received packets. A remote attacker could use this flaw to send a crafted packet to an ntpd client that would effectively disable synchronization with the server, or push arbitrary offset/delay measurements to modify the time on the client.

Отчет

This issue did not affect the versions of ntp as shipped with Red Hat Enterprise Linux 5 as they do not include the affected code, which was introduced in version 4.2.6 of NTP.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ntpNot affected
Red Hat Enterprise Linux 6ntpFixedRHSA-2016:006325.01.2016
Red Hat Enterprise Linux 7ntpFixedRHSA-2016:006325.01.2016

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-294
https://bugzilla.redhat.com/show_bug.cgi?id=1299442ntp: missing check for zero originate timestamp

EPSS

Процентиль: 89%
0.04814
Низкий

6.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 8 лет назад

NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packet with an origin timestamp set to zero.

CVSS3: 5.3
nvd
больше 8 лет назад

NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packet with an origin timestamp set to zero.

CVSS3: 5.3
debian
больше 8 лет назад

NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to ...

CVSS3: 5.3
github
больше 3 лет назад

NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packet with an origin timestamp set to zero.

oracle-oval
больше 9 лет назад

ELSA-2016-0063: ntp security update (IMPORTANT)

EPSS

Процентиль: 89%
0.04814
Низкий

6.4 Medium

CVSS2