CVE-2015-5219

CWE-704CWE-83510 documents8 sources
Severity
7.5HIGH
EPSS
2.2%
top 15.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 21
Latest updateMay 13

Description

The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages14 packages

Debianntp< 1:4.2.8p3+dfsg-1
NVDntp/ntp4.2.7
NVDnovell/leap42.2
NVDsuse/manager2.1

Also affects: Debian Linux 7.0, 8.0, Fedora 21, 22, 23, Ubuntu Linux 12.04, 14.04, 15.04, 15.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-38qh-x54p-8w2g: The ULOGTOD function in ntp2022-05-13
CVEList
CVE-2015-5219: The ULOGTOD function in ntp2017-07-21
OSV
CVE-2015-5219: The ULOGTOD function in ntp2017-07-21

📋Vendor Advisories

3
Ubuntu
NTP vulnerabilities2015-10-27
Red Hat
ntp: infinite loop in sntp processing crafted packet2015-08-25
Debian
CVE-2015-5219: ntp - The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform...2015

💬Community

3
Bugzilla
CVE-2017-16906 CVE-2017-16907 CVE-2017-16908 php-horde-horde: Multiple vulnerabilities2017-11-21
Bugzilla
CVE-2015-5219 ntp: infinite loop in sntp processing crafted packet [fedora-all]2015-08-25
Bugzilla
CVE-2015-5219 ntp: infinite loop in sntp processing crafted packet2015-08-19