Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2015-7851

Published: 28 January 2020

Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.

Notes

AuthorNote
mdeslaur
VMS-specific, not needed on Linux

Priority

Medium

CVSS 3 base score: 6.5

Status

Package Release Status
ntp
Launchpad, Ubuntu, Debian
upstream Needs triage

precise Not vulnerable

trusty Not vulnerable

vivid Not vulnerable

Patches:
upstream: https://github.com/ntp-project/ntp/commit/184516e143ce4448ddb5b9876dd372008cc779f6