NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "ntp",
"binary_version": "1:4.2.6.p5+dfsg-3ubuntu2.14.04.10"
},
{
"binary_name": "ntp-dbgsym",
"binary_version": "1:4.2.6.p5+dfsg-3ubuntu2.14.04.10"
},
{
"binary_name": "ntp-doc",
"binary_version": "1:4.2.6.p5+dfsg-3ubuntu2.14.04.10"
},
{
"binary_name": "ntpdate",
"binary_version": "1:4.2.6.p5+dfsg-3ubuntu2.14.04.10"
},
{
"binary_name": "ntpdate-dbgsym",
"binary_version": "1:4.2.6.p5+dfsg-3ubuntu2.14.04.10"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "ntp",
"binary_version": "1:4.2.8p4+dfsg-3ubuntu5.3"
},
{
"binary_name": "ntp-dbgsym",
"binary_version": "1:4.2.8p4+dfsg-3ubuntu5.3"
},
{
"binary_name": "ntp-doc",
"binary_version": "1:4.2.8p4+dfsg-3ubuntu5.3"
},
{
"binary_name": "ntpdate",
"binary_version": "1:4.2.8p4+dfsg-3ubuntu5.3"
},
{
"binary_name": "ntpdate-dbgsym",
"binary_version": "1:4.2.8p4+dfsg-3ubuntu5.3"
}
]
}