CVE编号
CVE-2015-5300利用情况
暂无补丁情况
官方补丁披露时间
2017-07-22漏洞描述
Network Time Protocol是一套用于通过网络同步计算机时钟的协议。Network Time Protocol存在安全绕过漏洞,允许远程攻击者进行中间人攻击绕过安全限制,执行未授权操作。
解决建议
用户可参考如下厂商提供的安全补丁以修复该漏洞:http://www.ntp.org/
参考链接 |
|
---|---|
http://aix.software.ibm.com/aix/efixes/security/ntp_advisory5.asc | |
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170684.html | |
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170926.html | |
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177507.html | |
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00059.html | |
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00060.html | |
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00020.html | |
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00038.html | |
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.html | |
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.html | |
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.html | |
http://lists.opensuse.org/opensuse-updates/2016-05/msg00114.html | |
http://rhn.redhat.com/errata/RHSA-2015-1930.html | |
http://seclists.org/bugtraq/2016/Feb/164 | |
http://support.ntp.org/bin/view/Main/NtpBug2956 | |
http://support.ntp.org/bin/view/Main/SecurityNotice#January_2016_NTP_4_2_8p5_Securit | |
http://www.debian.org/security/2015/dsa-3388 | |
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html | |
http://www.securityfocus.com/bid/77312 | |
http://www.securitytracker.com/id/1034670 | |
http://www.ubuntu.com/usn/USN-2783-1 | |
https://bto.bluecoat.com/security-advisory/sa113 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1271076 | |
https://ics-cert.us-cert.gov/advisories/ICSA-15-356-01 | |
https://security.netapp.com/advisory/ntap-20171004-0001/ | |
https://support.citrix.com/article/CTX220112 | |
https://www-01.ibm.com/support/docview.wss?uid=isg3T1023885 | |
https://www-01.ibm.com/support/docview.wss?uid=isg3T1024073 | |
https://www-01.ibm.com/support/docview.wss?uid=nas8N1021264 | |
https://www-01.ibm.com/support/docview.wss?uid=ssg1S1005821 | |
https://www-01.ibm.com/support/docview.wss?uid=swg21979393 | |
https://www-01.ibm.com/support/docview.wss?uid=swg21980676 | |
https://www-01.ibm.com/support/docview.wss?uid=swg21983501 | |
https://www-01.ibm.com/support/docview.wss?uid=swg21983506 | |
https://www.cs.bu.edu/~goldbe/NTPattack.html | |
https://www.freebsd.org/security/advisories/FreeBSD-SA-16:02.ntp.asc | |
https://www.ibm.com/support/home/docdisplay?lndocid=migr-5099428 | |
https://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html | |
https://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | ntp | ntp | * |
Up to (including) 4.2.8 |
|||||
运行在以下环境 | |||||||||
应用 | suse | linux_enterprise_debuginfo | 11 | - | |||||
运行在以下环境 | |||||||||
系统 | amazon_AMI | ntp | * |
Up to (excluding) 4.2.6p5-34.27.amzn1 |
|||||
运行在以下环境 | |||||||||
系统 | canonical | ubuntu_linux | 12.04 | - | |||||
运行在以下环境 | |||||||||
系统 | canonical | ubuntu_linux | 14.04 | - | |||||
运行在以下环境 | |||||||||
系统 | canonical | ubuntu_linux | 15.04 | - | |||||
运行在以下环境 | |||||||||
系统 | canonical | ubuntu_linux | 15.10 | - | |||||
运行在以下环境 | |||||||||
系统 | centos_6 | ntp | * |
Up to (excluding) 4.2.6p5-5.el6.centos.2 |
|||||
运行在以下环境 | |||||||||
系统 | debian | debian_linux | 7.0 | - | |||||
运行在以下环境 | |||||||||
系统 | debian | debian_linux | 8.0 | - | |||||
运行在以下环境 | |||||||||
系统 | debian | DPKG | * |
Up to (excluding) 1:4.2.8p4+dfsg-2 |
|||||
运行在以下环境 | |||||||||
系统 | debian_6 | ntp | * |
Up to (excluding) 1:4.2.6.p2+dfsg-1+deb6u4 |
|||||
运行在以下环境 | |||||||||
系统 | debian_7 | ntp | * |
Up to (excluding) 1:4.2.6.p5+dfsg-2+deb7u6 |
|||||
运行在以下环境 | |||||||||
系统 | debian_8 | ntp | * |
Up to (excluding) 1:4.2.6.p5+dfsg-7+deb8u1 |
|||||
运行在以下环境 | |||||||||
系统 | fedoraproject | fedora | 21 | - | |||||
运行在以下环境 | |||||||||
系统 | fedoraproject | fedora | 22 | - | |||||
运行在以下环境 | |||||||||
系统 | fedora_21 | ntp | * |
Up to (excluding) 4.2.6p5-34.fc21 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_22 | ntp | * |
Up to (excluding) 4.2.6p5-36.fc22 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_23 | ntp | * |
Up to (excluding) 4.2.6p5-34.fc23 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse | leap | 42.1 | - | |||||
运行在以下环境 | |||||||||
系统 | opensuse | opensuse | 13.2 | - | |||||
运行在以下环境 | |||||||||
系统 | opensuse_13.2 | ntp | * |
Up to (excluding) 4.2.8p7-25.15.1 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_42.1 | ntp | * |
Up to (excluding) 3.1.22-6.1 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_6 | ntp | * |
Up to (excluding) 4.2.6p5-5.el6_7.2 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_7 | ntp | * |
Up to (excluding) 4.2.6p5-5.el6_7.2 |
|||||
运行在以下环境 | |||||||||
系统 | redhat | enterprise_linux_desktop | 6.0 | - | |||||
运行在以下环境 | |||||||||
系统 | redhat | enterprise_linux_desktop | 7.0 | - | |||||
运行在以下环境 | |||||||||
系统 | redhat | enterprise_linux_hpc_node | 6.0 | - | |||||
运行在以下环境 | |||||||||
系统 | redhat | enterprise_linux_hpc_node | 7.0 | - | |||||
运行在以下环境 | |||||||||
系统 | redhat | enterprise_linux_hpc_node_eus | 7.1 | - | |||||
运行在以下环境 | |||||||||
系统 | redhat | enterprise_linux_server | 6.0 | - | |||||
运行在以下环境 | |||||||||
系统 | redhat | enterprise_linux_server | 7.0 | - | |||||
运行在以下环境 | |||||||||
系统 | redhat | enterprise_linux_server_eus | 6.7.z | - | |||||
运行在以下环境 | |||||||||
系统 | redhat | enterprise_linux_server_eus | 7.1 | - | |||||
运行在以下环境 | |||||||||
系统 | redhat | enterprise_linux_workstation | 6.0 | - | |||||
运行在以下环境 | |||||||||
系统 | redhat | enterprise_linux_workstation | 7.0 | - | |||||
运行在以下环境 | |||||||||
系统 | redhat_7 | ntp | * |
Up to (excluding) 0:4.2.6p5-5.el6_7.2 |
|||||
运行在以下环境 | |||||||||
系统 | sles_12 | ntp | * |
Up to (excluding) 4.2.8p8-14 |
|||||
运行在以下环境 | |||||||||
系统 | suse | linux_enterprise_desktop | 12 | - | |||||
运行在以下环境 | |||||||||
系统 | suse | linux_enterprise_server | 10 | - | |||||
运行在以下环境 | |||||||||
系统 | suse | linux_enterprise_server | 11 | - | |||||
运行在以下环境 | |||||||||
系统 | suse | linux_enterprise_server | 12 | - | |||||
运行在以下环境 | |||||||||
系统 | suse | linux_enterprise_software_development_kit | 12 | - | |||||
运行在以下环境 | |||||||||
系统 | suse | manager | 2.1 | - | |||||
运行在以下环境 | |||||||||
系统 | suse | manager_proxy | 2.1 | - | |||||
运行在以下环境 | |||||||||
系统 | suse | openstack_cloud | 5 | - | |||||
运行在以下环境 | |||||||||
系统 | suse | suse_linux_enterprise_server | 12 | - | |||||
运行在以下环境 | |||||||||
系统 | suse_11_SP4 | ntp | * |
Up to (excluding) 4.2.8p6-8.2 |
|||||
运行在以下环境 | |||||||||
系统 | suse_12 | ntp | * |
Up to (excluding) 3.1.12.4-8.2 |
|||||
运行在以下环境 | |||||||||
系统 | suse_12_SP1 | ntp | * |
Up to (excluding) 4.2.8p6-8.2 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_12.04_lts | ntp | * |
Up to (excluding) 1:4.2.6.p3+dfsg-1ubuntu3.6 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_14.04 | ntp | * |
Up to (excluding) 1:4.2.6.p5+dfsg-3ubuntu2.14.04.5 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_14.04_lts | ntp | * |
Up to (excluding) 1:4.2.6.p5+dfsg-3ubuntu2.14.04.5 |
|||||
- 攻击路径 远程
- 攻击复杂度 复杂
- 权限要求 无需权限
- 影响范围 有限影响
- EXP成熟度 未验证
- 补丁情况 官方补丁
- 数据保密性 无影响
- 数据完整性 无影响
- 服务器危害 无影响
- 全网数量 100
还没有评论,来说两句吧...