CVE-2015-5146
published 2017-08-24CVE-2015-5146: ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a…
PriorityP427medium5.3CVSS 3.0
AVNACHPRLUINSUCNINAH
EPSS
4.09%
89.6th percentile
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ntp | < ntp 1:4.2.8p3+dfsg-1 (bullseye) | ntp 1:4.2.8p3+dfsg-1 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| ntp | ntp | <= 4.2.8 | — |
| ntp | ntp | >= 0 < 1:4.2.8p3+dfsg-1 | 1:4.2.8p3+dfsg-1 |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.5 | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.5 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2015-10-27·CVSS 5.3
CVE-2015-5146 [MEDIUM] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Aleksis Kauppinen discovered that NTP incorrectly handled certain remote
config packets. In a non-default configuration, a remote authenticated
attacker could possibly use this issue to cause NTP to crash, resulting in
a denial of service. (CVE-2015-5146)
Miroslav Lichvar discovered that NTP incorrectly handled logconfig
directives. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to crash, resulting in a denial
of service. (CVE-2015-5194)
Miroslav Lichvar discovered that NTP incorrectly handled certain statistics
types. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to crash, resulting in a
Red Hat
ntp: ntpd control message crash on crafted NUL-byte in configuration directive (VU#668167)
vendor_redhat·2015-06-30·CVSS 5.3
CVE-2015-5146 [MEDIUM] CWE-20 ntp: ntpd control message crash on crafted NUL-byte in configuration directive (VU#668167)
ntp: ntpd control message crash on crafted NUL-byte in configuration directive (VU#668167)
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) - Will not fix
Package: ntp (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-5146: ntp - ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authe...
vendor_debian·2015·CVSS 5.3
CVE-2015-5146 [MEDIUM] CVE-2015-5146: ntp - ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authe...
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p3+dfsg-1)
GHSA
GHSA-8463-8xmw-64wf: ntpd in ntp before 4
ghsa_unreviewed·2022-05-14
CVE-2015-5146 [MEDIUM] CWE-20 GHSA-8463-8xmw-64wf: ntpd in ntp before 4
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.
OSV
CVE-2015-5146: ntpd in ntp before 4
osv·2017-08-24·CVSS 5.3
CVE-2015-5146 [MEDIUM] CVE-2015-5146: ntpd in ntp before 4
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.
OSV
ntp vulnerabilities
osv·2015-10-27·CVSS 5.3
CVE-2015-5146 [MEDIUM] ntp vulnerabilities
ntp vulnerabilities
Aleksis Kauppinen discovered that NTP incorrectly handled certain remote
config packets. In a non-default configuration, a remote authenticated
attacker could possibly use this issue to cause NTP to crash, resulting in
a denial of service. (CVE-2015-5146)
Miroslav Lichvar discovered that NTP incorrectly handled logconfig
directives. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to crash, resulting in a denial
of service. (CVE-2015-5194)
Miroslav Lichvar discovered that NTP incorrectly handled certain statistics
types. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to crash, resulting in a denial
of service. (CVE-2015-5195)
Miroslav Lichvar discove
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5146 ntp: ntpd control message crash on crafted NUL-byte in configuration directive (VU#668167)
bugzilla·2015-07-01·CVSS 5.3
CVE-2015-5146 [MEDIUM] CVE-2015-5146 ntp: ntpd control message crash on crafted NUL-byte in configuration directive (VU#668167)
CVE-2015-5146 ntp: ntpd control message crash on crafted NUL-byte in configuration directive (VU#668167)
A flaw was found in the way ntpd processed certain remote configuration packets. An attacker could use a specially crafted package to cause ntpd to crash if:
* ntpd enabled remote configuration
* The attacker had the knowledge of the configuration password
* The attacker had access to a computer entrusted to perform remote configuration
Note that remote configuration is disabled by default in NTP.
External References:
http://support.ntp.org/bin/view/Main/SecurityNotice#June_2015_NTP_Security_Vulnerabi
Discussion:
Created ntp tracking bugs for this issue:
Affects: fedora-all [bug 1238140]
---
Upstream issue:
http://bugs.ntp.org/show_bug.cgi?id=2853
---
ntp-4.2.6p5-33.fc21 ha
Bugzilla
CVE-2015-5146 ntp: ntpd control message crash on crafted NUL-byte in configuration directive (VU#668167) [fedora-all]
bugzilla·2015-07-01·CVSS 5.3
CVE-2015-5146 [MEDIUM] CVE-2015-5146 ntp: ntpd control message crash on crafted NUL-byte in configuration directive (VU#668167) [fedora-all]
CVE-2015-5146 ntp: ntpd control message crash on crafted NUL-byte in configuration directive (VU#668167) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2009-5146 openssl: memory leak in hostname TLS extension
bugzilla·2015-03-18
CVE-2009-5146 CVE-2009-5146 openssl: memory leak in hostname TLS extension
CVE-2009-5146 openssl: memory leak in hostname TLS extension
A memory leak flaw was fix in the hostname TLS extension:
https://github.com/openssl/openssl/commit/7587347bc48e7e8a1e800e48bb0a658f1557c424
This flaw was introduced with the backport of the TLS extension code first introduced in version 0.9.8k of openssl.
Additional information:
http://seclists.org/oss-sec/2015/q1/856
Discussion:
Statement:
This issue did not affect any versions of OpenSSL as shipped with Red Hat Enterprise Linux 5, 6, and 7.
http://bugs.ntp.org/show_bug.cgi?id=2853http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170926.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169167.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/166992.htmlhttp://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secuhttp://www.debian.org/security/2015/dsa-3388http://www.securityfocus.com/bid/75589http://www.securitytracker.com/id/1034168https://bugzilla.redhat.com/show_bug.cgi?id=1238136https://security.gentoo.org/glsa/201509-01https://security.netapp.com/advisory/ntap-20180731-0003/http://bugs.ntp.org/show_bug.cgi?id=2853http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170926.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169167.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/166992.htmlhttp://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secuhttp://www.debian.org/security/2015/dsa-3388http://www.securityfocus.com/bid/75589http://www.securitytracker.com/id/1034168https://bugzilla.redhat.com/show_bug.cgi?id=1238136https://security.gentoo.org/glsa/201509-01https://security.netapp.com/advisory/ntap-20180731-0003/
2017-08-24
Published