CVE-2005-2496 — Incorrect Privilege Assignment in Mills Ntpd
CWE-266 — Incorrect Privilege AssignmentCWE-269 — Improper Privilege Management10 documents8 sources
Severity
4.6MEDIUMNVD
EPSS
0.1%
top 74.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 2
Latest updateMay 1
Description
The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.
CVSS vector
AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4