Severity
5.9MEDIUMNVD
OSV6.5
EPSS
8.1%
top 7.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 30
Latest updateMay 14

Description

The getresponse function in ntpq in NTP versions before 4.2.8p9 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (infinite loop) via crafted packets with incorrect values.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

Debianntp/ntp< 1:4.2.8p7+dfsg-1
Ubuntuntp/ntp< 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10+1
NVDntp/ntp4.2.8+89
Palo Altopaloalto/pan-os

🔴Vulnerability Details

4
GHSA
GHSA-v47v-wc4h-2jgc: The getresponse function in ntpq in NTP versions before 42022-05-14
CVEList
CVE-2015-8158: The getresponse function in ntpq in NTP versions before 42017-01-30
OSV
CVE-2015-8158: The getresponse function in ntpq in NTP versions before 42017-01-30
OSV
ntp vulnerabilities2016-10-05

📋Vendor Advisories

7
Ubuntu
NTP vulnerabilities2016-10-05
Palo Alto
PAN-SA-2016-0019 NTP Vulnerabilities2016-08-15
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 20162016-01-28
BSD
FreeBSD-SA-16:09.ntp: Multiple vulnerabilities of ntp2016-01-27
Red Hat
ntp: potential infinite loop in ntpq2016-01-20

💬Community

2
Bugzilla
CVE-2015-8158 ntp: potential infinite loop in ntpq2016-01-20
Bugzilla
CVE-2015-7974 CVE-2015-8138 CVE-2015-7973 CVE-2015-7975 CVE-2015-7976 CVE-2015-7977 CVE-2015-7978 CVE-2015-7979 CVE-2015-8158 CVE-2015-8139 CVE-2015-8140 ntp: various flaws [fedora-all]2016-01-20
CVE-2015-8158 — NTP vulnerability | cvebase