First published: Mon Jan 30 2017(Updated: )
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NTP ntp | =4.1.2 | |
NTP ntp | <=4.2.8 | |
NTP ntp | =4.3.0 | |
NTP ntp | =4.3.1 | |
NTP ntp | =4.3.2 | |
NTP ntp | =4.3.3 | |
NTP ntp | =4.3.4 | |
NTP ntp | =4.3.5 | |
NTP ntp | =4.3.6 | |
NTP ntp | =4.3.7 | |
NTP ntp | =4.3.8 | |
NTP ntp | =4.3.9 | |
NTP ntp | =4.3.10 | |
NTP ntp | =4.3.11 | |
NTP ntp | =4.3.12 | |
NTP ntp | =4.3.13 | |
NTP ntp | =4.3.14 | |
NTP ntp | =4.3.15 | |
NTP ntp | =4.3.16 | |
NTP ntp | =4.3.17 | |
NTP ntp | =4.3.18 | |
NTP ntp | =4.3.19 | |
NTP ntp | =4.3.20 | |
NTP ntp | =4.3.21 | |
NTP ntp | =4.3.22 | |
NTP ntp | =4.3.23 | |
NTP ntp | =4.3.24 | |
NTP ntp | =4.3.25 | |
NTP ntp | =4.3.26 | |
NTP ntp | =4.3.27 | |
NTP ntp | =4.3.28 | |
NTP ntp | =4.3.29 | |
NTP ntp | =4.3.30 | |
NTP ntp | =4.3.31 | |
NTP ntp | =4.3.32 | |
NTP ntp | =4.3.33 | |
NTP ntp | =4.3.34 | |
NTP ntp | =4.3.35 | |
NTP ntp | =4.3.36 | |
NTP ntp | =4.3.37 | |
NTP ntp | =4.3.38 | |
NTP ntp | =4.3.39 | |
NTP ntp | =4.3.40 | |
NTP ntp | =4.3.41 | |
NTP ntp | =4.3.42 | |
NTP ntp | =4.3.43 | |
NTP ntp | =4.3.44 | |
NTP ntp | =4.3.45 | |
NTP ntp | =4.3.46 | |
NTP ntp | =4.3.47 | |
NTP ntp | =4.3.48 | |
NTP ntp | =4.3.49 | |
NTP ntp | =4.3.50 | |
NTP ntp | =4.3.51 | |
NTP ntp | =4.3.52 | |
NTP ntp | =4.3.53 | |
NTP ntp | =4.3.54 | |
NTP ntp | =4.3.55 | |
NTP ntp | =4.3.56 | |
NTP ntp | =4.3.57 | |
NTP ntp | =4.3.58 | |
NTP ntp | =4.3.59 | |
NTP ntp | =4.3.60 | |
NTP ntp | =4.3.61 | |
NTP ntp | =4.3.62 | |
NTP ntp | =4.3.63 | |
NTP ntp | =4.3.64 | |
NTP ntp | =4.3.65 | |
NTP ntp | =4.3.66 | |
NTP ntp | =4.3.67 | |
NTP ntp | =4.3.68 | |
NTP ntp | =4.3.69 | |
NTP ntp | =4.3.70 | |
NTP ntp | =4.3.71 | |
NTP ntp | =4.3.72 | |
NTP ntp | =4.3.73 | |
NTP ntp | =4.3.74 | |
NTP ntp | =4.3.75 | |
NTP ntp | =4.3.76 | |
NTP ntp | =4.3.77 | |
NTP ntp | =4.3.78 | |
NTP ntp | =4.3.79 | |
NTP ntp | =4.3.80 | |
NTP ntp | =4.3.81 | |
NTP ntp | =4.3.82 | |
NTP ntp | =4.3.83 | |
NTP ntp | =4.3.84 | |
NTP ntp | =4.3.85 | |
NTP ntp | =4.3.86 | |
NTP ntp | =4.3.87 | |
NTP ntp | =4.3.88 | |
NTP ntp | =4.3.89 | |
SUSE Linux Enterprise Debuginfo | =11-sp2 | |
SUSE Linux Enterprise Debuginfo | =11-sp3 | |
SUSE Linux Enterprise Debuginfo | =11-sp4 | |
SUSE Manager | =2.1 | |
Suse Manager Proxy | =2.1 | |
Novell Suse Openstack Cloud | =5 | |
openSUSE Leap | =42.1 | |
openSUSE openSUSE | =13.2 | |
SUSE Linux Enterprise Desktop | =12 | |
SUSE Linux Enterprise Desktop | =12-sp1 | |
SUSE Linux Enterprise Server | =10-sp4 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp4 | |
SUSE Linux Enterprise Server | =12-sp1 | |
SUSE SUSE Linux Enterprise Server | =12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.