Memory leak in ntp - CVE-2020-15025

 

Memory leak in ntp - CVE-2020-15025

Published: June 25, 2020 / Updated: June 29, 2020


Vulnerability identifier: #VU29293
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15025
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak when processing CMAC authentication. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

ntp
Gentoo Linux
Slackware Linux
Opensuse
openEuler
Flex System Chassis Management Module (CMM)
ntp
ntp-debugsource
ntp-perl
ntp-debuginfo
ntp-help

How to mitigate CVE-2020-15025

Install updates from vendor's website.

ntp - addressed in versions 4.2.8p15, 4.3.101
Flex System Chassis Management Module (CMM) - update to 2pet22a-2.5.20a
ntp - addressed in versions 4.2.8p14-3, 4.2.8p14-5, 4.2.8p14-6
ntp-debugsource - addressed in versions 4.2.8p14-3, 4.2.8p14-5, 4.2.8p14-6
ntp-perl - addressed in versions 4.2.8p14-3, 4.2.8p14-5, 4.2.8p14-6
ntp-debuginfo - addressed in versions 4.2.8p14-3, 4.2.8p14-5, 4.2.8p14-6
ntp-help - addressed in versions 4.2.8p14-3, 4.2.8p14-5, 4.2.8p14-6

External References

Related Security Bulletins