D15-92701
CVSS:
6.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
False Positive:
f
Variants:
2
Year:
2015
Description
This strike exploits a denial-of-service vulnerability in Network Time Protocol daemon (NTPD).
This vulnerability is due to the fact that "laddr" or "addr.%d" values from inside a mrulist command are not properly sanitized before supposing their length is less than 80 bytes in the decodenetnum() function.
An attacker exploiting this vulnerability could cause a denial-of-service condition on the target machine.