Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4953

Опубликовано: 02 июн. 2016
Источник: redhat
CVSS2: 2.6
EPSS Средний

Описание

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.

Отчет

This issue did not affect the versions of ntp as shipped with any Red Hat Enterprise Linux version as they already included a fix for this issue in the patch provided to fix the CVE-2015-7979 issue. The fix for this issue (developed by Red Hat) was different from the one provided by upstream, and thus ntp versions in RHEL are not affected by CVE-2016-4953.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ntpNot affected
Red Hat Enterprise Linux 6ntpNot affected
Red Hat Enterprise Linux 7ntpNot affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1340852ntp: bad authentication demobilizes ephemeral associations

EPSS

Процентиль: 97%
0.17245
Средний

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 10 лет назад

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.

CVSS3: 7.5
nvd
около 10 лет назад

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.

CVSS3: 7.5
debian
около 10 лет назад

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a deni ...

CVSS3: 7.5
github
около 4 лет назад

ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.

suse-cvrf
около 10 лет назад

Security update for ntp

EPSS

Процентиль: 97%
0.17245
Средний

2.6 Low

CVSS2