7.5
CVSSv3

CVE-2015-7848

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: 5 | VMScore: 850 | EPSS: 0.01499 | KEV: Not Included
Published: 06/01/2017 Updated: 21/11/2024

Vulnerability Summary

An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authentication code and a valid timestamp. When processed by the NTP daemon, it leads to an immediate crash.

Vulnerable Product Search on Vulmon Subscribe to Product

ntp ntp-dev 4.3.70

Vendor Advisories

An integer overflow can occur in NTP-dev4370 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet The crafted packet needs to have the correct message authentication code and a valid timestamp When processed by the NTP daemon, it leads to an immediate crash ...
Multiple Cisco products incorporate a version of the ntpd package Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition or modify the time being advertised by a device acting as a network time protocol (NTP) server On October 21st, 2 ...