CVE-2015-7855: Input Validation
It was found that NTP's decodenetnum() would abort with an assertion failure when processing a mode 6 or mode 7 packet containing an unusually long data value where a network address was expected. This could allow an authenticated attacker to crash ntpd.
External References:
https://github.com/ntp-project/ntp/blob/stable/NEWS#L295 http://support.ntp.org/bin/view/Main/SecurityNotice#October2015NTPSecurityVulner
Other sources
The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7855?
CVE-2015-7855 has a severity level that could potentially allow an authenticated attacker to crash the ntpd service.
How do I fix CVE-2015-7855?
To address CVE-2015-7855, upgrade NTP to version 4.2.8 or later.
Which software is affected by CVE-2015-7855?
CVE-2015-7855 affects versions of NTP from 4.2.0 to 4.2.8 and other specific Siemens products.
What is the impact of exploiting CVE-2015-7855?
Exploiting CVE-2015-7855 could lead to a denial of service by crashing the ntpd process.
Is CVE-2015-7855 easy to exploit?
CVE-2015-7855 requires authentication, making it less accessible for unauthenticated attackers but still a risk.