Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
CVE-2015-5219
CVE information
Published
Last Modified
CVSSv2.0 Severity
CVSSv3.1 Severity
Impact Analysis
Description
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet..
CVSSv2.0 Score
- Severity
- Medium
- Base Score
- 5/10
- Exploit Score
- 10/10
- Access Vector
- Network
- Access Complexity
- Low
- Authentication Required
- None
- Impact Score
- 2.9/10
- Confidentiality Impact
- None
- Availability Impact
- Partial
- Integrity Impact
- None
CVSSv3.1 Score
- Severity
- High
- Base Score
- 7.5/10
- Exploit Score
- 3.9/10
- Access Vector
- Network
- Access Complexity
- Low
- Privileges Required
- None
- Impact Score
- 3.6/10
- Confidentiality Impact
- None
- Availability Impact
- High
- Integrity Impact
- None
- Scope
- Unchanged
- User Interaction
- None
Products Affected
CPE | Affected | Vulnerable | Excluding | Edit |
---|---|---|---|---|
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:suse:manager_proxy:2.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp3:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:suse:manager:2.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp2:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:ltss:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:suse:openstack_cloud:5:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:ltss:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*: |
Yes
|
- | - | |
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:redhat:enterprise_linux_hpc_node:6.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:redhat:enterprise_linux_hpc_node:7.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*: |
Yes
|
- | - | |
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:a:ntp:ntp:*:p355:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:novell:leap:42.2:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* |
Yes
|
- | - | |
cpe:2.3:o:oracle:linux:6:-:*:*:*:*:*:* |
Yes
|
- | - |
References
- https://www-01.ibm.com/support/docview.wss?uid=swg21989542
- https://www-01.ibm.com/support/docview.wss?uid=swg21988706
- https://www-01.ibm.com/support/docview.wss?uid=swg21986956
- https://www-01.ibm.com/support/docview.wss?uid=swg21985122
- https://www-01.ibm.com/support/docview.wss?uid=isg3T1024157
- https://www.ibm.com/support/home/docdisplay?lndocid=migr-5099409
- https://github.com/ntp-project/ntp/commit/5f295cd05c3c136d39f5b3e500a2d781bdbb59c8
- https://bugzilla.redhat.com/show_bug.cgi?id=1255118
- http://www.ubuntu.com/usn/USN-2783-1
- http://www.securityfocus.com/bid/76473
- http://www.openwall.com/lists/oss-security/2015/08/25/3
- http://www.debian.org/security/2015/dsa-3388
- http://rhn.redhat.com/errata/RHSA-2016-2583.html
- http://rhn.redhat.com/errata/RHSA-2016-0780.html
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00153.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/166992.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-October/169167.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170926.html
- http://aix.software.ibm.com/aix/efixes/security/ntp_advisory4.asc
- http://bk1.ntp.org/ntp-dev/?PAGE=patch&REV=51786731Gr4-NOrTBC_a_uXO4wuGhg
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdf
- https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11