CVE-2015-7854: Buffer Overflow
Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted key file.
Other sources
The following flaw was found in ntpd:
A potential buffer overflow vulnerability exists in the password management functionality of ntp. A specially crafted key file could cause a buffer overflow potentially resulting in memory being modified. An attacker could provide a malicious password to trigger this vulnerability.
External References:
http://talosintel.com/reports/TALOS-2015-0065/ http://support.ntp.org/bin/view/Main/SecurityNotice#October2015NTPSecurityVulner
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7854?
The severity of CVE-2015-7854 is considered high due to the potential for denial of service and remote code execution.
How do I fix CVE-2015-7854?
To fix CVE-2015-7854, upgrade NTP to version 4.2.8p4 or 4.3.77 or later.
Which versions of NTP are affected by CVE-2015-7854?
Versions of NTP 4.2.x before 4.2.8p4 and 4.3.x before 4.3.77 are affected by CVE-2015-7854.
What type of attacks can CVE-2015-7854 enable?
CVE-2015-7854 can enable denial of service attacks and potentially allow remote authenticated users to execute arbitrary code.
Is there a workaround for CVE-2015-7854 if I cannot upgrade?
There are no specific workarounds for CVE-2015-7854; upgrading to a fixed version is the recommended solution.