Vulnerability Name: | CVE-2005-2496 (CCN-22035) | ||||||||||||||||
Assigned: | 2005-08-25 | ||||||||||||||||
Published: | 2005-08-25 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended. | ||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2005-2496 Source: CCN Type: NTP Software Downloads Web page Software Downloads Source: CCN Type: RHSA-2006-0393 ntp security update Source: CCN Type: SA16602 NTP Incorrect Group Permissions Security Issue Source: SECUNIA Type: Vendor Advisory 16602 Source: SECUNIA Type: UNKNOWN 21464 Source: CCN Type: SECTRACK ID: 1016679 xntpd `-u` Switch May Cause the Daemon to Run With Incorrect Group Privileges Source: SECTRACK Type: UNKNOWN 1016679 Source: CCN Type: ASA-2006-169 ntp security update (RHSA-2006-0393) Source: DEBIAN Type: UNKNOWN DSA-801 Source: DEBIAN Type: DSA-801 ntp -- programming error Source: MANDRAKE Type: UNKNOWN MDKSA-2005:156 Source: CCN Type: NTP Web site NTP: The Network Time Protocol Source: OSVDB Type: UNKNOWN 19055 Source: CCN Type: OSVDB ID: 19055 NTP ntpd -u Group Permission Weakness Source: REDHAT Type: UNKNOWN RHSA-2006:0393 Source: BID Type: UNKNOWN 14673 Source: CCN Type: BID-14673 NTPD Insecure Privileges Vulnerability Source: FEDORA Type: Vendor Advisory FEDORA-2005-812 Source: CCN Type: USN-175-1 ntp server vulnerability Source: VUPEN Type: UNKNOWN ADV-2005-1561 Source: XF Type: UNKNOWN ntp-incorrect-group-permissions(22035) Source: XF Type: UNKNOWN ntp-incorrect-group-permissions(22035) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9669 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |