vulnerability

NTP: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CVE-2015-7854)

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Aug 7, 2017
Added
Feb 23, 2023
Modified
Mar 1, 2023

Description

Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted key file.

Solutions

ntp-upgrade-4_2_8ntp-upgrade-4_3_77
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.