← Back

CVE-2015-7703

nvd nist
Published: Jul 24, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.

Affected (45)

Products: Ntp: Ntp · Oracle: Linux · Debian: Debian Linux · +2 more
Show all products
1 product
Ntp
1 product
Linux
1 product
Debian Linux
4 products
Clustered Data Ontap
Data Ontap
Oncommand Performance Manager
Oncommand Unified Manager
6 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Eus
Enterprise Linux Server Tus
Enterprise Linux Workstation
Configuration A
19 vulnerable
Vulnerable SoftwareAffected Versions
Ntp
From 4.2.0 to 4.2.8
From 4.3.0 to 4.3.77
Version 4.2.8
Version 4.2.8 p1-beta1
Version 4.2.8 p1-beta2
Version 4.2.8 p1-beta3
Version 4.2.8 p1-beta4
Version 4.2.8 p1-beta5
Version 4.2.8 p1-rc1
Version 4.2.8 p1-rc2
Version 4.2.8 p1
Version 4.2.8 p2-rc1
Version 4.2.8 p2-rc2
Version 4.2.8 p2-rc3
Version 4.2.8 p2
Version 4.2.8 p3-rc1
Version 4.2.8 p3-rc2
Version 4.2.8 p3-rc3
Version 4.2.8 p3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 7.0
Version 8.0
Version 9.0
Configuration D
4 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
Configuration E
18 vulnerable

References (20)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Issue TrackingThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.