CVE-2015-5300

The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
opensuseleap
42.1
opensuseopensuse
13.2
susemanager
2.1
susemanager_proxy
2.1
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_hpc_node
6.0
redhatenterprise_linux_hpc_node
7.0
redhatenterprise_linux_hpc_node_eus
7.1
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_eus
6.7.z:z
redhatenterprise_linux_server_eus
7.1
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
debiandebian_linux
7.0
debiandebian_linux
8.0
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
15.04
canonicalubuntu_linux
15.10
ntpntp
𝑥
≤ 4.2.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ntp
bullseye
1:4.2.8p15+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ntp
precise
Fixed 1:4.2.6.p3+dfsg-1ubuntu3.6
released
trusty
Fixed 1:4.2.6.p5+dfsg-3ubuntu2.14.04.5
released
vivid
Fixed 1:4.2.6.p5+dfsg-3ubuntu6.2
released
wily
Fixed 1:4.2.6.p5+dfsg-3ubuntu8.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
yast2-ntp-client
suse enterprise sap 12
3.1.12.4-8.2
fixed
suse enterprise sap 12 SP1
3.1.22-6.2
fixed
suse enterprise server 12
3.1.12.4-8.2
fixed
suse enterprise server 12 SP1
3.1.22-6.2
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
ntp
RHEL 6
0:4.2.6p5-5.el6_7.2
fixed
RHEL 7
0:4.2.6p5-19.el7_1.3
fixed
ntp-doc
RHEL 6
0:4.2.6p5-5.el6_7.2
fixed
RHEL 7
0:4.2.6p5-19.el7_1.3
fixed
ntp-perl
RHEL 6
0:4.2.6p5-5.el6_7.2
fixed
RHEL 7
0:4.2.6p5-19.el7_1.3
fixed
ntpdate
RHEL 6
0:4.2.6p5-5.el6_7.2
fixed
RHEL 7
0:4.2.6p5-19.el7_1.3
fixed
sntp
RHEL 7
0:4.2.6p5-19.el7_1.3
fixed
Common Weakness Enumeration
References