cbcvebase.
CVE-2015-5219
published 2017-07-21

CVE-2015-5219: The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianntp< ntp 1:4.2.8p3+dfsg-1 (bullseye)ntp 1:4.2.8p3+dfsg-1 (bullseye)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
novellleap
ntpntp<= 4.2.7
ntpntp>= 0 < 1:4.2.8p3+dfsg-11:4.2.8p3+dfsg-1
ntpntp>= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.51:4.2.6.p5+dfsg-3ubuntu2.14.04.5
opensuseleap
oraclelinux
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_hpc_node
redhatenterprise_linux_hpc_node
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation
suselinux_enterprise_debuginfo

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH