CVE-2015-5146

ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:ntp:ntp:*:p2:*:*:*:*:*:*

History

No history.

Information

Published : 2017-08-24 20:29

Updated : 2023-12-10 12:15


NVD link : CVE-2015-5146

Mitre link : CVE-2015-5146

CVE.ORG link : CVE-2015-5146


JSON object : View

Products Affected

ntp

  • ntp

debian

  • debian_linux

fedoraproject

  • fedora
CWE
CWE-20

Improper Input Validation