Junglewise Threat Intelligence

CVE-2015-7975: NTP nextvar function memory corruption denial of service

CVE-2015-7975 · Severity: medium · CVSS 6.2 · Published 2017-01-30

Vendors: NTP Project.

Executive brief

A vulnerability exists in the Network Time Protocol (NTP) software, which is used to synchronize clocks across computer networks. An attacker can exploit this flaw to cause the NTP service to crash, leading to a denial of service. This can disrupt time-sensitive operations and network logging that rely on accurate time synchronization.

Technical details

A memory buffer validation vulnerability (CWE-119) exists in the nextvar function of the NTP daemon (ntpd). The component fails to properly validate the length of input strings, leading to a potential buffer overflow or similar memory corruption when processing specific variables. An attacker with local access can exploit this to trigger an application crash, resulting in a denial of service. The issue is resolved in NTP versions 4.2.8p6 and 4.3.90.

Affected products

  • NTP Project ntp Before 4.2.8p6, 4.3.x before 4.3.90

Timeline

  • 2016-01-27: advisory: Cisco Security Advisory published
  • 2017-01-30: disclosed: NVD publication date

References