CVE-2015-7692: Input Validation
Published Aug 7, 2017
·Updated
The cryptoxmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Affected Software
45 affected components
NTP ntp>=4.2.0<4.2.8
NTP ntp>=4.3.0<4.3.77
NTP ntp=4.2.8
NTP ntp=4.2.8-p1
NTP ntp=4.2.8-p1-beta1
NTP ntp=4.2.8-p1-beta2
NTP ntp=4.2.8-p1-beta3
NTP ntp=4.2.8-p1-beta4
NTP ntp=4.2.8-p1-beta5
NTP ntp=4.2.8-p1-rc1
NTP ntp=4.2.8-p1-rc2
NTP ntp=4.2.8-p2
NTP ntp=4.2.8-p2-rc1
NTP ntp=4.2.8-p2-rc2
NTP ntp=4.2.8-p2-rc3
NTP ntp=4.2.8-p3
NTP ntp=4.2.8-p3-rc1
NTP ntp=4.2.8-p3-rc2
NTP ntp=4.2.8-p3-rc3
Oracle Linux=6
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
NetApp Oncommand Performance Manager
NetApp Oncommand Unified Manager Clustered Data Ontap
NetApp Clustered Data ONTAP
NetApp Data Ontap 7-mode
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Aus=7.7
redhat Enterprise Linux Server Eus=7.3
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Eus=7.7
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Server Tus=7.7
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Event History
Aug 7, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7692?
CVE-2015-7692 is categorized as a denial of service vulnerability that can lead to a crash of the NTP service.
2
How do I fix CVE-2015-7692?
To remediate CVE-2015-7692, update NTP to version 4.2.8p4 or later for 4.2.x, or to version 4.3.77 or later for 4.3.x.
3
What systems are affected by CVE-2015-7692?
CVE-2015-7692 affects NTP versions 4.2.0 to 4.2.8p3 and versions 4.3.0 to 4.3.76.
4
What type of vulnerability is CVE-2015-7692?
CVE-2015-7692 is a denial of service vulnerability that allows remote attackers to crash the NTP service.
5
Is CVE-2015-7692 related to any other vulnerabilities?
CVE-2015-7692 is related to CVE-2014-9750, as it exists due to an incomplete fix for that vulnerability.