Debian Ntp vulnerabilities
88 known vulnerabilities affecting debian/ntp.
Total CVEs
88
CISA KEV
0
Public exploits
7
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH24MEDIUM40LOW21
Vulnerabilities
Page 3 of 5
CVE-2015-7851P3MEDIUMCVSS 6.5fixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7851 [MEDIUM] CVE-2015-7851: ntp - Directory traversal vulnerability in the save_config function in ntpd in ntp_con...
Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
debian
CVE-2015-5219P3LOWCVSS 7.5fixed in ntp 1:4.2.8p3+dfsg-1 (bullseye)2015
CVE-2015-5219 [HIGH] CVE-2015-5219: ntp - The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform...
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p3+dfsg-1)
debian
CVE-2019-8936P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p12+dfsg-4 (bullseye)2019
CVE-2019-8936 [HIGH] CVE-2019-8936: ntp - NTP through 4.2.8p12 has a NULL Pointer Dereference.
NTP through 4.2.8p12 has a NULL Pointer Dereference.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p12+dfsg-4)
debian
CVE-2015-7691P3MEDIUMCVSS 5.8fixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7691 [MEDIUM] CVE-2015-7691: ntp - The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4...
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
debian
CVE-2016-7433P3MEDIUMCVSS 5.3fixed in ntp 1:4.2.8p9+dfsg-1 (bullseye)2016
CVE-2016-7433 [MEDIUM] CVE-2016-7433: ntp - NTP before 4.2.8p9 does not properly perform the initial sync calculations, whic...
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."
Scope: local
bullseye: resolved (fixed in 1:4.2.8p9+dfsg-1)
debian
CVE-2015-7692P3MEDIUMCVSS 5.8fixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7692 [MEDIUM] CVE-2015-7692: ntp - The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4...
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
debian
CVE-2014-9751P3MEDIUMCVSS 6.8fixed in ntp 1:4.2.6.p5+dfsg-4 (bullseye)2014
CVE-2014-9751 [MEDIUM] CVE-2014-9751: ntp - The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 o...
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a
debian
CVE-2017-6462P3LOWCVSS 7.8fixed in ntp 1:4.2.8p10+dfsg-1 (bullseye)2017
CVE-2017-6462 [HIGH] CVE-2017-6462: ntp - Buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock dri...
Buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock driver in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via a crafted /dev/datum device.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p10+dfsg-1)
debian
CVE-2015-8138P3MEDIUMCVSS 5.3fixed in ntp 1:4.2.8p7+dfsg-1 (bullseye)2015
CVE-2015-8138 [MEDIUM] CVE-2015-8138: ntp - NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the...
NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packet with an origin timestamp set to zero.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
debian
CVE-2015-7701P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7701 [HIGH] CVE-2015-7701: ntp - Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, an...
Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption).
Scope: local
bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
debian
CVE-2016-4956P4HIGHCVSS 7.2fixed in ntp 1:4.2.8p8+dfsg-1 (bullseye)2016
CVE-2016-4956 [HIGH] CVE-2016-4956: ntp - ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of serv...
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p8+dfsg-1)
debian
CVE-2016-2518P4MEDIUMCVSS 5.3fixed in ntp 1:4.2.8p7+dfsg-1 (bullseye)2016
CVE-2016-2518 [MEDIUM] CVE-2016-2518: ntp - The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 a...
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
debian
CVE-2016-7431P3MEDIUMCVSS 5.3fixed in ntp 1:4.2.8p9+dfsg-1 (bullseye)2016
CVE-2016-7431 [MEDIUM] CVE-2016-7431: ntp - NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protec...
NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p9+dfsg-1)
debian
CVE-2016-1549P3MEDIUMCVSS 6.5fixed in ntp 1:4.2.8p7+dfsg-1 (bullseye)2016
CVE-2016-1549 [MEDIUM] CVE-2016-1549: ntp - A malicious authenticated peer can create arbitrarily-many ephemeral association...
A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p4 and earlier and NTPsec 3e160db8dc248a0bcb053b56a80167dc742d2b74 and a5fb34b9cc89b92a8fef2f459004865c93bb7f92 and modify a victim's clock.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
debian
CVE-2015-8139P3MEDIUMCVSS 5.3fixed in ntp 1:4.2.8p7+dfsg-1 (bullseye)2015
CVE-2015-8139 [MEDIUM] CVE-2015-8139: ntp - ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps a...
ntpq in NTP before 4.2.8p7 allows remote attackers to obtain origin timestamps and then impersonate peers via unspecified vectors.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
debian
CVE-2016-1547P4MEDIUMCVSS 5.3fixed in ntp 1:4.2.8p7+dfsg-1 (bullseye)2016
CVE-2016-1547 [MEDIUM] CVE-2016-1547: ntp - An off-path attacker can cause a preemptible client association to be demobilize...
An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer. This is true even if authentication is enabled.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7
debian
CVE-2016-4955P4MEDIUMCVSS 5.9fixed in ntp 1:4.2.8p8+dfsg-1 (bullseye)2016
CVE-2016-4955 [MEDIUM] CVE-2016-4955: ntp - ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers...
ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p8+dfsg-1)
debian
CVE-2015-7852P4MEDIUMCVSS 5.9fixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7852 [MEDIUM] CVE-2015-7852: ntp - ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attacker...
ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
debian
CVE-2016-9311P4MEDIUMCVSS 5.9fixed in ntp 1:4.2.8p9+dfsg-1 (bullseye)2016
CVE-2016-9311 [MEDIUM] CVE-2016-9311: ntp - ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote atta...
ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted packet.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p9+dfsg-1)
debian
CVE-2015-7973P3LOWCVSS 6.5fixed in ntp 1:4.2.8p7+dfsg-1 (bullseye)2015
CVE-2015-7973 [MEDIUM] CVE-2015-7973: ntp - NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, a...
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
debian