Description
Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-335-1 | ntp security update |
EUVD |
EUVD-2015-7749 | Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T07:59:00.648Z
Reserved: 2015-10-16T00:00:00.000Z
Link: CVE-2015-7851
No data.
Status : Modified
Published: 2020-01-28T17:15:12.053
Modified: 2024-11-21T02:37:31.947
Link: CVE-2015-7851
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD