ZeroHour

CVE-2016-2518

CVSS 3.1
5.3 medium
EPSS
15%p97
Published
()
Modified
Description

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.

Vendors
ntpdebiannetapporacleredhatfreebsdsiemens
Products
ntp, debian linux, clustered data ontap, data ontap, oncommand balance, oncommand performance manager, oncommand unified manager for clustered data ontap, communications user data repository, linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.