First published: Wed Jun 24 2020(Updated: )
NTP is vulnerable to a denial of service, caused by a memory leak when a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file in ntpd. By sending specially-crafted packets, a remote authenticated attacker could exploit this vulnerability to consume all available memory resources.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data Risk Manager | <=2.0.6 | |
NTP ntp | >=4.3.97<4.3.101 | |
NTP ntp | =4.2.8-p11 | |
NTP ntp | =4.2.8-p12 | |
NTP ntp | =4.2.8-p13 | |
NTP ntp | =4.2.8-p14 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Netapp Cloud Backup | ||
Netapp Steelstore Cloud Integrated Storage | ||
Netapp 8300 Firmware | ||
Netapp 8300 | ||
Netapp 8700 Firmware | ||
Netapp 8700 | ||
Netapp A400 Firmware | ||
Netapp A400 | ||
Netapp H410c Firmware | ||
Netapp H410c | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H300e Firmware | ||
Netapp H300e | ||
Netapp H500e Firmware | ||
Netapp H500e | ||
Netapp H700e Firmware | ||
Netapp H700e | ||
Netapp H410s Firmware | ||
Netapp H410s | ||
Oracle ZFS Storage Appliance Kit | =8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15025 is a vulnerability in ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 that allows remote attackers to cause a denial of service by consuming all available memory resources.
CVE-2020-15025 has a severity rating of 4.9 (Medium).
The software affected by CVE-2020-15025 includes IBM Data Risk Manager (version up to 2.0.6) and NTP (versions 4.2.8-p11 to 4.2.8-p15 and 4.3.97 to 4.3.101).
To fix CVE-2020-15025, apply the necessary patches provided by the vendor or update to a fixed version of the software.
You can find more information about CVE-2020-15025 at the following references: [IBM X-Force](https://exchange.xforce.ibmcloud.com/vulnerabilities/184004), [IBM Support](https://www.ibm.com/support/pages/node/6335281), [openSUSE Security Announce](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.html).