VYPR
Medium severity5.3NVD Advisory· Published Aug 24, 2017· Updated Jun 17, 2026

CVE-2015-5146

CVE-2015-5146

Description

ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • NTP/NTP2 versions
    cpe:2.3:a:ntp:ntp:*:p2:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ntp:ntp:*:p2:*:*:*:*:*:*range: <=4.2.8
    • (no CPE)range: <4.2.8p3
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
  • NTP/ntpdllm-fuzzy
    Range: <4.2.8p3

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.