CVE-2015-5146
Summary
| CVE | CVE-2015-5146 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-24 20:29:00 UTC |
| Updated | 2018-08-02 01:29:00 UTC |
| Description | ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 21 | All | All | All |
| Operating System | Fedoraproject | Fedora | 22 | All | All | All |
| Operating System | Fedoraproject | Fedora | 23 | All | All | All |
| Operating System | Fedoraproject | Fedora | 21 | All | All | All |
| Operating System | Fedoraproject | Fedora | 22 | All | All | All |
| Operating System | Fedoraproject | Fedora | 23 | All | All | All |
| Application | Ntp | Ntp | All | p2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 22 Update: ntp-4.2.6p5-33.fc22 | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| support.ntp.org/bin/view/Main/SecurityNotice | CONFIRM | support.ntp.org | Vendor Advisory |
| Debian -- Security Information -- DSA-3388-1 ntp | DEBIAN | www.debian.org | Third Party Advisory |
| NTP CVE-2015-5146 Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE-2015-5146 Network Time Protocol Daemon (ntpd) Denial of Service Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Gentoo Security | GENTOO | security.gentoo.org | Mitigation, Third Party Advisory, VDB Entry |
| Bug 2853 – Crafted remote config packet can crash some versions of ntpd. | CONFIRM | bugs.ntp.org | Issue Tracking, Third Party Advisory |
| Ntpd Remote Configuration Bug Lets Remote Authenticated Users on the Local Network Cause the Target Service to Crash - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| 1238136 – (CVE-2015-5146) CVE-2015-5146 ntp: ntpd control message crash on crafted NUL-byte in configuration directive (VU#668167) | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 21 Update: ntp-4.2.6p5-34.fc21 | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| [SECURITY] Fedora 23 Update: ntp-4.2.6p5-33.fc23 | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.