MEDIUM · 4.6

CVE-2005-2496

The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with diffe...

Vulnerability Description

The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Dave MillsNtpd<= 4.2.0.a.2004-06-17_4.fc3

References

FAQ

What is CVE-2005-2496?

CVE-2005-2496 is a vulnerability with a CVSS score of 4.6 (MEDIUM). The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with diffe...

How severe is CVE-2005-2496?

CVE-2005-2496 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-2496?

Check the references section above for vendor advisories and patch information. Affected products include: Dave Mills Ntpd.