CVE-2015-7851
28.01.2020, 17:15
Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.
Vendor | Product | Version |
---|---|---|
ntp | ntp | 4.2.0 ≤ 𝑥 < 4.2.8 |
ntp | ntp | 4.3.0 ≤ 𝑥 < 4.3.77 |
ntp | ntp | 4.2.8:p1 |
ntp | ntp | 4.2.8:p1-beta1 |
ntp | ntp | 4.2.8:p1-beta2 |
ntp | ntp | 4.2.8:p1-beta3 |
ntp | ntp | 4.2.8:p1-beta4 |
ntp | ntp | 4.2.8:p1-beta5 |
ntp | ntp | 4.2.8:p1-rc1 |
ntp | ntp | 4.2.8:p1-rc2 |
ntp | ntp | 4.2.8:p2 |
ntp | ntp | 4.2.8:p2-rc1 |
ntp | ntp | 4.2.8:p2-rc2 |
ntp | ntp | 4.2.8:p2-rc3 |
ntp | ntp | 4.2.8:p3 |
ntp | ntp | 4.2.8:p3-rc1 |
ntp | ntp | 4.2.8:p3-rc2 |
ntp | ntp | 4.2.8:p3-rc3 |
𝑥
= Vulnerable software versions

Debian Releases
References