NTP BUG 2918: Potential path traversal vulnerability in the config file saving of ntpd on VMS

Last update: March 2, 2022 17:28 UTC (616623bea)


Summary

Resolved 4.2.8p4 21 Oct 2015
References Bug 2918 CVE-2015-7851
Affects All ntp-4 releases running under VMS up to, but not including 4.2.8p4,
and 4.3.0 up to, but not including 4.3.77.
Resolved in 4.2.8p4.
CVSS2 Score 5.2, worst case AV:N/AC:H/Au:M/C:N/I:P/A:C

Description

If ntpd is configured to allow remote configuration, and if the (possibly spoofed) IP address is allowed to send remote configuration requests, and if the attacker knows the remote configuration password or if ntpd was configured to disable authentication, then an attacker can send a set of packets to ntpd that may cause ntpd to overwrite files.


Mitigation


Credit

This weakness was discovered by Yves Younan of Cisco Talos.


Timeline