VDB
BDU%3A2023-02659
BDU%3A2023-02659
PUBLISHED
CVSS 5.099999904632568 MEDIUM
Уязвимость функции mstolfp() (libntp/mstolfp.c) программы мониторинга операций ntpq реализации протокола синхронизации времени NTP, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
5.099999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Novell Inc., Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», АО «ИВК», Network Time Foundation | Red Hat Enterprise Linux, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Server for SAP Applications, Suse Linux Enterprise Server, Debian GNU/Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), Альт 8 СП (запись в едином реестре российских программ №4305), NTP, АЛЬТ СП 10 |
Timeline
- May 17, 2023 CVE Published
- Jan 27, 2026 CVE Updated
References
- https://github.com/spwpun/ntp-4.2.8p15-cves/blob/main/CVE-2023-26554 url
- https://github.com/spwpun/ntp-4.2.8p15-cves/issues/1#issuecomment-1506667321 url
- https://access.redhat.com/security/cve/cve-2023-26554 url
- https://security-tracker.debian.org/tracker/CVE-2023-26554 url
- https://www.suse.com/es-es/security/cve/CVE-2023-26554.html url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 url
- https://altsp.su/obnovleniya-bezopasnosti/ url