CVE-2015-5194: Input Validation
It was found that ntpd could crash due to an uninitialized variable when processing malformed logconfig configuration commands, for example:
ntpq -c ":config logconfig a"
Upstream patch:
http://bk.ntp.org/ntp-dev/?PAGE=patch&REV=4c4fc141LwvcoGp-lLGhkAFp3ZvtrA
Other sources
The logconfigcommand function in ntpparser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5194?
CVE-2015-5194 has been classified as a moderate severity vulnerability.
How do I fix CVE-2015-5194?
To fix CVE-2015-5194, ensure you apply the patches provided by your operating system vendor.
Which versions of ntpd are affected by CVE-2015-5194?
ntpd versions prior to 4.2.8 are vulnerable to CVE-2015-5194.
What systems are impacted by CVE-2015-5194?
CVE-2015-5194 affects various systems including Fedora, SUSE, Red Hat, and Debian distributions.
Can CVE-2015-5194 cause crashes?
Yes, CVE-2015-5194 can lead to crashes of ntpd when processing malformed logconfig commands.