CVE-2017-6459

medium

Description

The Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via vectors related to an argument with multiple null bytes.

References

https://support.apple.com/HT208144

http://www.securitytracker.com/id/1038123

http://www.securityfocus.com/bid/97076

http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secu

http://support.ntp.org/bin/view/Main/NtpBug3382

Details

Source: Mitre, NVD

Published: 2017-03-27

Updated: 2017-10-24

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium