Debian Ntp vulnerabilities
88 known vulnerabilities affecting debian/ntp.
Total CVEs
88
CISA KEV
0
Public exploits
7
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH24MEDIUM40LOW21
Vulnerabilities
Page 5 of 5
CVE-2016-7428P4MEDIUMCVSS 4.3fixed in ntp 1:4.2.8p9+dfsg-1 (bullseye)2016
CVE-2016-7428 [MEDIUM] CVE-2016-7428: ntp - ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service ...
ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via the poll interval in a broadcast packet.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p9+dfsg-1)
debian
CVE-2016-7427P4MEDIUMCVSS 4.3fixed in ntp 1:4.2.8p9+dfsg-1 (bullseye)2016
CVE-2016-7427 [MEDIUM] CVE-2016-7427: ntp - The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9...
The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via a crafted broadcast mode packet.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p9+dfsg-1)
debian
CVE-2015-7975P4MEDIUMCVSS 6.2fixed in ntp 1:4.2.8p7+dfsg-1 (bullseye)2015
CVE-2015-7975 [MEDIUM] CVE-2015-7975: ntp - The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not prop...
The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, which allows an attacker to cause a denial of service (application crash).
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
debian
CVE-2016-7429P4LOWCVSS 3.7fixed in ntp 1:4.2.8p9+dfsg-1 (bullseye)2016
CVE-2016-7429 [LOW] CVE-2016-7429: ntp - NTP before 4.2.8p9 changes the peer structure to the interface it receives the r...
NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source) by sending a response for a source to an interface the source does not use.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p9+dfsg-1)
debian
CVE-2004-0657P4MEDIUMCVSS 5.0fixed in ntp 4.0 (bullseye)2004
CVE-2004-0657 [MEDIUM] CVE-2004-0657: ntp - Integer overflow in the NTP daemon (NTPd) before 4.0 causes the NTP server to re...
Integer overflow in the NTP daemon (NTPd) before 4.0 causes the NTP server to return the wrong date/time offset when a client requests a date/time that is more than 34 years away from the server's time.
Scope: local
bullseye: resolved (fixed in 4.0)
debian
CVE-2015-1799P4MEDIUMCVSS 4.3fixed in ntp 1:4.2.6.p5+dfsg-6 (bullseye)2015
CVE-2015-1799 [MEDIUM] CVE-2015-1799: ntp - The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP ...
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 3.x and 4.x before 4.2.8p2 performs state-variable updates upon receiving certain invalid packets, which makes it easier for man-in-the-middle attackers to cause a denial of service (synchronization loss) by spoofing the source IP address of a peer.
Scope: local
bullseye: resolved (fixed in
debian
CVE-2015-1798P4LOWCVSS 1.8fixed in ntp 1:4.2.6.p5+dfsg-6 (bullseye)2015
CVE-2015-1798 [LOW] CVE-2015-1798: ntp - The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP ...
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MAC.
Scope: local
bullseye: resolved (fixed in 1:4.2.6.p5+dfsg-6)
debian
CVE-2005-2496P4MEDIUMCVSS 4.6fixed in ntp 1:4.2.0a+stable-2sarge1 (bullseye)2005
CVE-2005-2496 [MEDIUM] CVE-2005-2496: ntp - The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using...
The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.
Scope: local
bullseye: resolved (fixed in 1:4.2.0a+stable-2sarge1)
debian
← Previous5 / 5