CVE-2015-7977 (NVD)

2017-01-30

ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.

Products Ubuntu_linux, Debian_linux, Fedora, Freebsd, Clustered_data_ontap, Oncommand_balance, Ntp, Linux, Tim_4r\-Ie_dnp3_firmware, Tim_4r\-Ie_firmware
Type NULL Pointer Dereference (CWE-476)
First patch - None (likely due to unavailable code)
Links http://www.securitytracker.com/id/1034782
http://www.securityfocus.com/bid/81815
http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176434.html
https://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdf
http://www.debian.org/security/2016/dsa-3629