CVE-2015-7849: Use After Free
The following flaw was found in ntpd:
An exploitable use-after-free vulnerability exists in the password management functionality of the Network Time Protocol. A specially crafted key file could cause a buffer overflow resulting in memory corruption. An attacker could provide a malicious password file to trigger this vulnerability.
External References:
http://talosintel.com/reports/TALOS-2015-0054/ http://support.ntp.org/bin/view/Main/SecurityNotice#October2015NTPSecurityVulner
Other sources
Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7849?
CVE-2015-7849 is classified as a critical vulnerability due to its potential for remote exploitation leading to memory corruption.
How do I fix CVE-2015-7849?
To fix CVE-2015-7849, you should update the ntp software to version 4.2.8 or later.
Which versions are affected by CVE-2015-7849?
CVE-2015-7849 affects ntp versions prior to 4.2.8 as well as specific beta and release candidates up to version 4.3.77.
What type of vulnerability is CVE-2015-7849?
CVE-2015-7849 is a use-after-free vulnerability found in the password management functionality of the Network Time Protocol.
Can I exploit CVE-2015-7849 through any means?
Yes, an attacker can exploit CVE-2015-7849 by using a specially crafted key file that triggers a buffer overflow.