← Back

CVE-2015-7848

nvd nist
Published: Jan 6, 2017Modified: May 23, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authentication code and a valid timestamp. When processed by the NTP daemon, it leads to an immediate crash.

Affected (24)

5 products
Clustered Data Ontap
Data Ontap Operating In 7 Mode
Oncommand Balance
Oncommand Performance Manager
Oncommand Unified Manager
1 product
Ntp
Configuration A
5 vulnerable
Configuration B
19 vulnerable
Vulnerable SoftwareAffected Versions
Ntp
From 4.0 to 4.2.8
From 4.3.0 to 4.3.77
Version 4.2.8
Version 4.2.8 p1-beta1
Version 4.2.8 p1-beta2
Version 4.2.8 p1-beta3
Version 4.2.8 p1-beta4
Version 4.2.8 p1-beta5
Version 4.2.8 p1-rc1
Version 4.2.8 p1-rc2
Version 4.2.8 p1
Version 4.2.8 p2-rc1
Version 4.2.8 p2-rc2
Version 4.2.8 p2-rc3
Version 4.2.8 p2
Version 4.2.8 p3-rc1
Version 4.2.8 p3-rc2
Version 4.2.8 p3-rc3
Version 4.2.8 p3

References (10)

Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
ExploitTechnical DescriptionThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.