Lucene search

K
archlinuxArch LinuxASA-201507-5
HistoryJul 07, 2015 - 12:00 a.m.

ntp: denial of service

2015-07-0700:00:00
Arch Linux
lists.archlinux.org
16

0.011 Low

EPSS

Percentile

84.8%

Under limited and specific circumstances an attacker can send a crafted
remote-configuration packet containing a NUL-byte to cause a vulnerable
ntpd instance to crash. This requires each of the following to be true:

  • ntpd set up to allow for remote configuration (not allowed by
    default)
  • knowledge of the configuration password
  • access to a computer entrusted to perform remote configuration
OSVersionArchitecturePackageVersionFilename
anyanyanyntp< 4.2.8.p3-1UNKNOWN