CVE Vulnerabilities

CVE-2005-2496

Published: Sep 02, 2005 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.

Affected Software

Name Vendor Start Version End Version
Ntpd Dave_mills * 4.2.0.a.2004-06-17_4.fc3 (including)
Red Hat Enterprise Linux 4 RedHat ntp-0:4.2.0.a.20040617-4.EL4.1 *

References