HIGH · 7.5

CVE-2015-3405

ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is betwee...

Vulnerability Description

ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
NtpNtp4.2.8
DebianDebian Linux7.0
OpensuseSuse Linux Enterprise Server11.0
Opensuse ProjectSuse Linux Enterprise Desktop11.0
SuseSuse Linux Enterprise Server11.0
FedoraprojectFedora21
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux For Ibm Z Systems6.0
RedhatEnterprise Linux For Power Big Endian6.0
RedhatEnterprise Linux For Scientific Computing6.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server From Rhui 66.0
RedhatEnterprise Linux Workstation6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-3405?

CVE-2015-3405 is a vulnerability with a CVSS score of 7.5 (HIGH). ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is betwee...

How severe is CVE-2015-3405?

CVE-2015-3405 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-3405?

Check the references section above for vendor advisories and patch information. Affected products include: Ntp Ntp, Debian Debian Linux, Opensuse Suse Linux Enterprise Server, Opensuse Project Suse Linux Enterprise Desktop, Suse Suse Linux Enterprise Server.