Vulnerability CVE-2017-6459


Published: 2017-03-27

Description:
The Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via vectors related to an argument with multiple null bytes.

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
NTP -> NTP 

 References:
http://support.ntp.org/bin/view/Main/NtpBug3382
http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secu
http://www.securityfocus.com/bid/97076
http://www.securitytracker.com/id/1038123
https://support.apple.com/HT208144

Copyright 2024, cxsecurity.com

 

Back to Top