CVE-2015-5219
21.07.2017, 14:29
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.Enginsight
| Vendor | Product | Version |
|---|---|---|
| suse | manager | 2.1 |
| suse | manager_proxy | 2.1 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_hpc_node | 6.0 |
| redhat | enterprise_linux_hpc_node | 7.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.04 |
| canonical | ubuntu_linux | 15.10 |
| ntp | ntp | 𝑥 ≤ 4.2.7 |
| novell | leap | 42.2 |
| opensuse | leap | 42.1 |
| siemens | tim_4r-ie_firmware | * |
| siemens | tim_4r-id_dnp3_firmware | * |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References