Last update: April 22, 2024 18:49 UTC (7e7bd5857)
Resolved | 4.2.8p10 | 21 Mar 2017 |
---|---|---|
References | Bug 3389 | CVE-2017-6464 |
Affects | All versions of NTP-4, up to but not including ntp-4.2.8p10, and ntp-4.3.0 up to, but not including ntp-4.3.94. |
Resolved in 4.2.8p10. |
CVSS2 Score | MED 4.6 | AV:N/AC:H/Au:M/C:N/I:N/A:C |
CVSS3 Score | MED 4.2 | CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H |
A vulnerability found in the NTP server makes it possible for an authenticated remote user to crash ntpd
via a malformed mode configuration directive.
ntpd
instances, and auto-restart ntpd
(without -g
) if it stops running.This weakness was discovered by Cure53.