Scheduled maintenance: Some features related to account registration and licensing may be temporarily unavailable from Friday (May 8) at 1 PM to Sunday (May 10) at 5 PM (PST).
HomeDefectsLIN6-10798
Fixed

LIN6-10798 : Security Advisory - ntp - CVE-2015-7978

Created: Jan 27, 2016    Updated: Dec 3, 2018
Resolved Date: Mar 25, 2016
Previous ID: SCP6-674
Found In Version: 6.0.0.27
Fix Version: 6.0.0.29
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace

Description

A stack-based buffer overflow was found in the way ntpd processed 'ntpdc reslist' commands that queried restriction lists with a large amount of entries. A remote attacker could use this flaw to crash the ntpd process.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-7978  

Other Downloads