VDB
CVE-2015-7975
CVE-2015-7975
PUBLISHED
CVSS 6.199999809265137 MEDIUM
The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, which allows an attacker to cause a denial of service (application crash).
EPSS 0.64% · 48.7th percentile
Risk Scores
CVSS 3.0
6.199999809265137
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.64%
48.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | ntp | 0, 1:4.2.6.p5+dfsg-3ubuntu8.1, 1:4.2.6.p5+dfsg-3ubuntu9 |
Timeline
- Dec 31, 2015 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 15, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Apr 7, 2023 EPSS Score
- May 30, 2023 EPSS Score
- Jul 22, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2015-7975 third-party-advisory
- http://support.ntp.org/bin/view/Main/SecurityNotice#January_2016_NTP_4_2_8p6_Securit third-party-advisory
- http://www.talosintel.com/reports/TALOS-2016-0072/ third-party-advisory
- https://ubuntu.com/security/notices/USN-3096-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2015-7975 third-party-advisory