CVE-2015-7976: Medium severity NTP ntp vulnerability
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7976?
CVE-2015-7976 is considered to have a medium severity due to its potential for unspecified impact using special character filtering issues.
Which versions are affected by CVE-2015-7976?
CVE-2015-7976 affects NTP versions 4.1.2, 4.2.x before 4.2.8p6, and several versions in the 4.3 series up to 4.3.78.
How do I fix CVE-2015-7976?
To resolve CVE-2015-7976, upgrade NTP to versions 4.2.8p6 or later, or to the latest 4.3.x version.
What is the impact of exploiting CVE-2015-7976?
Exploitation of CVE-2015-7976 could lead to unauthorized actions by manipulating filename inputs.
Is there a workaround for CVE-2015-7976?
A temporary workaround for CVE-2015-7976 is to avoid using the ntpq saveconfig command with untrusted filenames.