The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3.12 Ntp_advisory4 | — | — | Feb 4, 2016 | Feb 4, 2016 |
| Aix 6.1.6 Ntp_advisory4 | — | — | Nov 3, 2017 | Jul 21, 2017 |
| Aix 6.1.9 Ntp_advisory4 | — | — | Feb 4, 2016 | Feb 4, 2016 |
| Aix 7.1.0 Ntp_advisory4 | — | — | Nov 3, 2017 | Jul 21, 2017 |
| Aix 7.1.3 Ntp_advisory4 | — | — | Feb 4, 2016 | Feb 4, 2016 |
| Aix 7.1.4 Ntp_advisory4 | — | — | Feb 4, 2016 | Feb 4, 2016 |
| Aix 7.2.0 Ntp_advisory4 | — | — | Feb 4, 2016 | Feb 4, 2016 |
| Debian | — | Upgrade ntp | Nov 9, 2015 | Oct 27, 2015 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jan 19, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade ntpdateUpgrade ntp | Nov 30, 2017 | Jul 21, 2017 |
| Ibm Aix | — | Apply the fix or workaround for ntp_advisory4 | Nov 30, 2017 | Jul 21, 2017 |
| Ntp | — | Upgrade to the latest version of NTP | Feb 23, 2023 | Jul 21, 2017 |
| Oracle_linux | — | Upgrade ntpdateUpgrade ntp-docUpgrade ntpUpgrade ntp-perlUpgrade sntp | Jul 21, 2017 | Jul 21, 2017 |
| Redhat_linux | — | Upgrade ntp-docUpgrade ntp-debuginfoUpgrade ntpdateUpgrade sntpUpgrade ntpNo solution existsUpgrade ntp-perl | Jul 1, 2017 | Oct 27, 2015 |
| Suse | — | Upgrade yast2-ntp-clientUpgrade ntpUpgrade ntp-debugsourceUpgrade ntp-debuginfoUpgrade ntp-doc | May 17, 2016 | Oct 27, 2015 |
| Ubuntu | — | Upgrade ntp | Nov 9, 2015 | Oct 27, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub