Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-7433

Опубликовано: 21 нояб. 2016
Источник: redhat
CVSS3: 2.9
CVSS2: 1.2

Описание

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

A flaw was found in the way ntpd calculated the root delay. A remote attacker could send a specially-crafted spoofed packet to cause denial of service or in some special cases even crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5ntpNot affected
Red Hat Enterprise Linux 6ntpFixedRHSA-2017:025206.02.2017
Red Hat Enterprise Linux 7ntpFixedRHSA-2017:025206.02.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-682
https://bugzilla.redhat.com/show_bug.cgi?id=1397347ntp: Broken initial sync calculations regression

2.9 Low

CVSS3

1.2 Low

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 9 лет назад

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

CVSS3: 5.3
nvd
почти 9 лет назад

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

CVSS3: 5.3
debian
почти 9 лет назад

NTP before 4.2.8p9 does not properly perform the initial sync calculat ...

CVSS3: 5.3
github
больше 3 лет назад

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

oracle-oval
почти 9 лет назад

ELSA-2017-0252: ntp security update (MODERATE)

2.9 Low

CVSS3

1.2 Low

CVSS2