VYPR

rpm package

opensuse/ntp&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/ntp&distro=openSUSE%20Tumbleweed

Vulnerabilities (78)

  • CVE-2015-7850MedAug 7, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by pointing the key file at the log file.

  • CVE-2015-7849HigAug 7, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets.

  • CVE-2015-7705CriAug 7, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.

  • CVE-2015-7704HigAug 7, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.

  • CVE-2015-7702MedAug 7, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.

  • CVE-2015-7701HigAug 7, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption).

  • CVE-2015-7692HigAug 7, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.

  • CVE-2015-7691HigAug 7, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-

  • CVE-2015-7703HigJul 24, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote co

  • CVE-2015-5300HigJul 21, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to

  • CVE-2017-6464MedMar 27, 2017
    affected < 4.2.8p15-7.2fixed 4.2.8p15-7.2

    NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.

  • CVE-2017-6463MedMar 27, 2017
    affected < 4.2.8p15-7.2fixed 4.2.8p15-7.2

    NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash) via an invalid setting in a :config directive, related to the unpeer option.

  • CVE-2017-6462HigMar 27, 2017
    affected < 4.2.8p15-7.2fixed 4.2.8p15-7.2

    Buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock driver in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via a crafted /dev/datum device.

  • CVE-2017-6460HigMar 27, 2017
    affected < 4.2.8p15-7.2fixed 4.2.8p15-7.2

    Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspecified impact via a long flagstr variable in a restriction list response.

  • CVE-2017-6458HigMar 27, 2017
    affected < 4.2.8p15-7.2fixed 4.2.8p15-7.2

    Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.

  • CVE-2017-6451HigMar 27, 2017
    affected < 4.2.8p15-7.2fixed 4.2.8p15-7.2

    The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which trigger an out-of-bounds mem

  • CVE-2016-2519MedJan 30, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (ntpd abort) by a large request data value, which triggers the ctl_getitem function to return a NULL value.

  • CVE-2016-2518MedJan 30, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.

  • CVE-2016-2517MedJan 30, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or

  • CVE-2016-2516MedJan 30, 2017
    affected < 4.2.8p9-1.1fixed 4.2.8p9-1.1

    NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.