VDB
CVE-2005-2496
CVE-2005-2496
PUBLISHED
CVSS 4.599999904632568 MEDIUM
The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.
EPSS 0.44% · 36.6th percentile
Risk Scores
CVSS 2.0
4.599999904632568
EPSS Score
0.44%
36.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| dave_mills | ntpd | 0 |
| n/a | n/a | n/a |
Timeline
- Sep 2, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- RHSA-2006:0393 vendor-advisory
- 19055 vdb
- 1016679 vdb
- ADV-2005-1561 vdb
- MDKSA-2005:156 vendor-advisory
- DSA-801 vendor-advisory
- http://secunia.com/advisories/16602 advisory
- http://www.securityfocus.com/bid/14673 technical
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9669 technical
- http://www.securityspace.com/smysecure/catid.html?id=55155 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22035 technical
- https://nvd.nist.gov/vuln/detail/CVE-2005-2496 advisory
- http://secunia.com/advisories/21464 url