Severity
7.5HIGH
EPSS
2.2%
top 15.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 21
Latest updateMay 13
Description
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages14 packages
Also affects: Debian Linux 7.0, 8.0, Fedora 21, 22, 23, Ubuntu Linux 12.04, 14.04, 15.04, 15.10