Описание
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1:4.2.8p4+dfsg-3ubuntu6 |
| esm-infra-legacy/trusty | released | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 |
| esm-infra/xenial | released | 1:4.2.8p4+dfsg-3ubuntu5.3 |
| precise | released | 1:4.2.6.p3+dfsg-1ubuntu3.11 |
| precise/esm | not-affected | 1:4.2.6.p3+dfsg-1ubuntu3.11 |
| trusty | released | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 |
| trusty/esm | released | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 |
| upstream | released | 4.2.8p6 |
| vivid | ignored | end of life |
| vivid/stable-phone-overlay | ignored | end of life |
Показывать по
EPSS
4 Medium
CVSS2
4.3 Medium
CVSS3
Связанные уязвимости
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4 ...
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
EPSS
4 Medium
CVSS2
4.3 Medium
CVSS3