The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3.12 Ntp_advisory4 | — | — | Feb 4, 2016 | Feb 4, 2016 |
| Aix 6.1.6 Ntp_advisory4 | — | — | Nov 3, 2017 | Jul 21, 2017 |
| Aix 6.1.9 Ntp_advisory4 | — | — | Feb 4, 2016 | Feb 4, 2016 |
| Aix 7.1.0 Ntp_advisory4 | — | — | Nov 3, 2017 | Jul 21, 2017 |
| Aix 7.1.3 Ntp_advisory4 | — | — | Feb 4, 2016 | Feb 4, 2016 |
| Aix 7.1.4 Ntp_advisory4 | — | — | Feb 4, 2016 | Feb 4, 2016 |
| Aix 7.2.0 Ntp_advisory4 | — | — | Feb 4, 2016 | Feb 4, 2016 |
| Debian | — | Upgrade ntp | Nov 9, 2015 | Oct 27, 2015 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 19, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade ntpUpgrade ntpdate | Nov 30, 2017 | Jul 21, 2017 |
| Ibm Aix | — | Apply the fix or workaround for ntp_advisory4 | Nov 30, 2017 | Jul 21, 2017 |
| Ntp | — | Upgrade to the latest version of NTP | Feb 23, 2023 | Jul 21, 2017 |
| Oracle_linux | — | Upgrade ntp-perlUpgrade ntpdateUpgrade sntpUpgrade ntpUpgrade ntp-doc | Jul 21, 2017 | Jul 21, 2017 |
| Redhat_linux | — | Upgrade ntpdateUpgrade ntp-docUpgrade ntp-debuginfoUpgrade sntpUpgrade ntp-perlNo solution existsUpgrade ntp | Jul 1, 2017 | Oct 27, 2015 |
| Suse | — | Upgrade ntp-docUpgrade yast2-ntp-clientUpgrade ntp-debugsourceUpgrade ntpUpgrade ntp-debuginfo | May 17, 2016 | Oct 27, 2015 |
| Ubuntu | — | Upgrade ntp | Nov 9, 2015 | Oct 27, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub