CVE-2015-3405
Last modified
CVE-2015-3405 is a vulnerability of currently unknown severity. ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.. EPSS estimates a 5.29% chance of exploitation in the next 30 days.
Description
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ntp | Ntp | 4.2.8 | P1 |
| Ntp | Ntp | 4.3.0 | — |
| Ntp | Ntp | 4.3.1 | — |
| Ntp | Ntp | 4.3.2 | — |
| Ntp | Ntp | 4.3.3 | — |
| Ntp | Ntp | 4.3.4 | — |
| Ntp | Ntp | 4.3.5 | — |
| Ntp | Ntp | 4.3.6 | — |
| Ntp | Ntp | 4.3.7 | — |
| Ntp | Ntp | 4.3.8 | — |
| Ntp | Ntp | 4.3.9 | — |
| Ntp | Ntp | 4.3.10 | — |
| Ntp | Ntp | 4.3.11 | — |
| Debian | Debian Linux | 7.0 | — |
| Debian | Debian Linux | 8.0 | — |
| Opensuse | Suse Linux Enterprise Server | 11.0 | Sp3 |
| Opensuse Project | Suse Linux Enterprise Desktop | 11.0 | Sp3 |
| Suse | Suse Linux Enterprise Server | 11.0 | Sp3 |
| Fedoraproject | Fedora | 21 | — |
| Redhat | Enterprise Linux Desktop | 6.0 | — |
| Redhat | Enterprise Linux For Ibm Z Systems | 6.0 | — |
| Redhat | Enterprise Linux For Power Big Endian | 6.0 | — |
| Redhat | Enterprise Linux For Scientific Computing | 6.0 | — |
| Redhat | Enterprise Linux Server | 6.0 | — |
| Redhat | Enterprise Linux Server From Rhui 6 | 6.0 | — |
| Redhat | Enterprise Linux Workstation | 6.0 | — |
References
- http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=55199296N2gFqH1Hm5GOnhrk9YpyggThird Party Advisory, Vendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156248.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00000.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1459.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2015-2231.htmlThird Party Advisory, VDB Entry
- http://www.debian.org/security/2015/dsa-3223Third Party Advisory
- http://www.debian.org/security/2015/dsa-3388Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/04/23/14Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/74045Third Party Advisory, VDB Entry
- https://bugs.ntp.org/show_bug.cgi?id=2797Issue Tracking, Third Party Advisory, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1210324Issue Tracking, Patch, Third Party Advisory, VDB Entry
- http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=55199296N2gFqH1Hm5GOnhrk9YpyggThird Party Advisory, Vendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156248.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00000.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1459.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2015-2231.htmlThird Party Advisory, VDB Entry
- http://www.debian.org/security/2015/dsa-3223Third Party Advisory
- http://www.debian.org/security/2015/dsa-3388Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/04/23/14Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/74045Third Party Advisory, VDB Entry
- https://bugs.ntp.org/show_bug.cgi?id=2797Issue Tracking, Third Party Advisory, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1210324Issue Tracking, Patch, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-3405?
How severe is CVE-2015-3405?
How do I fix CVE-2015-3405?
Are you affected by CVE-2015-3405?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
