HIGH · 7.5

CVE-2015-5219

The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infini...

Vulnerability Description

The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
FedoraprojectFedora21
SuseLinux Enterprise Debuginfo11
SuseLinux Enterprise Server10
SuseManager2.1
SuseManager Proxy2.1
SuseOpenstack Cloud5
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Hpc Node6.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Workstation6.0
DebianDebian Linux7.0
CanonicalUbuntu Linux12.04
NtpNtp<= 4.2.7
NovellLeap42.2
OpensuseLeap42.1
SiemensTim 4R-Ie FirmwareAll versions
SiemensTim 4R-Ie-
SiemensTim 4R-Id Dnp3 FirmwareAll versions
SiemensTim 4R-Id Dnp3-
OracleLinux6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-5219?

CVE-2015-5219 is a vulnerability with a CVSS score of 7.5 (HIGH). The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infini...

How severe is CVE-2015-5219?

CVE-2015-5219 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-5219?

Check the references section above for vendor advisories and patch information. Affected products include: Fedoraproject Fedora, Suse Linux Enterprise Debuginfo, Suse Linux Enterprise Server, Suse Manager, Suse Manager Proxy.