CVE-2005-2496 Affecting ntp package, versions <1:4.2.0a+stable-2sarge1


Severity

Recommended
0.0
medium
0
10

Based on Debian security rating.

Threat Intelligence

EPSS
0.06% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN9-NTP-373197
  • published2 Sept 2005
  • disclosed2 Sept 2005

Introduced: 2 Sep 2005

CVE-2005-2496  (opens in a new tab)

How to fix?

Upgrade Debian:9 ntp to version 1:4.2.0a+stable-2sarge1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream ntp package and not the ntp package as distributed by Debian. See How to fix? for Debian:9 relevant fixed versions and status.

The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.

CVSS Base Scores

version 3.1