Vulnerability Description
The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 16.04 LTS allows local users with access to the ntp account to write to arbitrary files and consequently gain privileges via vectors involving statistics directory cleanup.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 12.04 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/141913/NTP-Privilege-Escalation.htmlExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/81552Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1034808Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-3096-1Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/ntp/+bug/1528050Issue TrackingPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1382369Issue Tracking
- http://packetstormsecurity.com/files/141913/NTP-Privilege-Escalation.htmlExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/81552Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1034808Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-3096-1Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/ntp/+bug/1528050Issue TrackingPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1382369Issue Tracking
FAQ
What is CVE-2016-0727?
CVE-2016-0727 is a vulnerability with a CVSS score of 7.8 (HIGH). The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3u...
How severe is CVE-2016-0727?
CVE-2016-0727 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-0727?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux.