CVE-2015-3405
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 5.29% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-331
- Affected
- ntp/ntp · debian/debian linux · opensuse/suse linux enterprise server · opensuse project/suse linux enterprise desktop · suse/suse linux enterprise server · fedoraproject/fedora · redhat/enterprise linux desktop · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for power big endian · redhat/enterprise linux for scientific computing · redhat/enterprise linux server · redhat/enterprise linux server from rhui 6 · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=55199296N2gFqH1Hm5GOnhrk9YpyggThird Party Advisory, Vendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156248.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00000.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1459.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2015-2231.htmlThird Party Advisory, VDB Entry
- http://www.debian.org/security/2015/dsa-3223Third Party Advisory
- http://www.debian.org/security/2015/dsa-3388Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/04/23/14Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/74045Third Party Advisory, VDB Entry
- https://bugs.ntp.org/show_bug.cgi?id=2797Issue Tracking, Third Party Advisory, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1210324Issue Tracking, Patch, Third Party Advisory, VDB Entry
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03886en_us
- http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=55199296N2gFqH1Hm5GOnhrk9YpyggThird Party Advisory, Vendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156248.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00000.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1459.htmlThird Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2015-2231.htmlThird Party Advisory, VDB Entry
- http://www.debian.org/security/2015/dsa-3223Third Party Advisory
- http://www.debian.org/security/2015/dsa-3388Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/04/23/14Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/74045Third Party Advisory, VDB Entry
- https://bugs.ntp.org/show_bug.cgi?id=2797Issue Tracking, Third Party Advisory, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1210324Issue Tracking, Patch, Third Party Advisory, VDB Entry
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03886en_us
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.