CVE-2015-7703

NameCVE-2015-7703
DescriptionThe "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-335-1, DSA-3388-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ntp (PTS)wheezy1:4.2.6.p5+dfsg-2+deb7u6fixed
wheezy (security)1:4.2.6.p5+dfsg-2+deb7u7fixed
jessie (security), jessie1:4.2.6.p5+dfsg-7+deb8u2fixed
stretch1:4.2.8p10+dfsg-3+deb9u1fixed
buster, sid1:4.2.8p10+dfsg-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ntpsource(unstable)1:4.2.8p4+dfsg-1medium
ntpsourcejessie1:4.2.6.p5+dfsg-7+deb8u1mediumDSA-3388-1
ntpsourcesqueeze1:4.2.6.p2+dfsg-1+deb6u4mediumDLA-335-1
ntpsourcewheezy1:4.2.6.p5+dfsg-2+deb7u6mediumDSA-3388-1

Notes

http://support.ntp.org/bin/view/Main/SecurityNotice#October_2015_NTP_Security_Vulner
https://github.com/ntp-project/ntp/commit/5dea6ff160c7e8f7cb038619ccccd28c3a8df637
https://github.com/ntp-project/ntp/commit/cdae0f1369ade98dc7ae912a0f1953b6e533cb88

Search for package or bug name: Reporting problems