ZeroHour

CVE-2016-4957

CVSS 3.1
7.5 high
EPSS
45%p99
Published
()
Modified
Description

ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.

Vendors
ntporaclesusenovellopensuse
Products
ntp, solaris, manager proxy, openstack cloud, suse manager, leap, opensuse, linux enterprise desktop, linux enterprise server
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.