CVE-2015-7703
Publication date 22 October 2015
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.
Status
Package | Ubuntu Release | Status |
---|---|---|
ntp | ||
14.04 LTS trusty |
Fixed 1:4.2.6.p5+dfsg-3ubuntu2.14.04.5
|
|
Notes
Patch details
Package | Patch details |
---|---|
ntp |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | High |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
References
Related Ubuntu Security Notices (USN)
- USN-2783-1
- NTP vulnerabilities
- 27 October 2015