CVE-2015-7975 PUBLISHED

The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, which allows an attacker to cause a denial of service (application crash).

EPSS 0.41% · 61.2th percentile

Risk Scores

EPSS Score
0.41%
61.2th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSntp0, 1:4.2.6.p5+dfsg-3ubuntu8, 1:4.2.6.p5+dfsg-3ubuntu8.1

Timeline

References

Open in Interactive Console →