CVE Vulnerabilities

CVE-2005-2496

Published: Sep 02, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.

Affected Software

NameVendorStart VersionEnd Version
NtpdDave_mills*4.2.0.a.2004-06-17_4.fc3 (including)
Red Hat Enterprise Linux 4RedHatntp-0:4.2.0.a.20040617-4.EL4.1*

References