CVE Vulnerabilities

CVE-2015-5219

Incorrect Type Conversion or Cast

Published: Jul 21, 2017 | Modified: Feb 13, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
3.3 LOW
AV:A/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.

Weakness

The product does not correctly convert an object, resource, or structure from one type to a different type.

Affected Software

Name Vendor Start Version End Version
Fedora Fedoraproject 21 (including) 21 (including)
Fedora Fedoraproject 22 (including) 22 (including)
Fedora Fedoraproject 23 (including) 23 (including)
Red Hat Enterprise Linux 6 RedHat ntp-0:4.2.6p5-10.el6 *
Red Hat Enterprise Linux 7 RedHat ntp-0:4.2.6p5-25.el7 *
Ntp Ubuntu devel *
Ntp Ubuntu precise *
Ntp Ubuntu trusty *
Ntp Ubuntu upstream *
Ntp Ubuntu vivid *
Ntp Ubuntu vivid/stable-phone-overlay *
Ntp Ubuntu wily *

References