F5 Networks BIG-IP : NTP vulnerability (K07082049)

Medium Nessus Plugin ID 105399

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

Buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock driver in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via a crafted /dev/datum device. (CVE-2017-6462)

Solution

Upgrade to one of the non-vulnerable versions listed in the F5 Solution K07082049.

See Also

https://support.f5.com/csp/#/article/K07082049

Plugin Details

Severity: Medium

ID: 105399

File Name: f5_bigip_SOL07082049.nasl

Version: 3.4

Type: local

Published: 2017/12/21

Modified: 2018/04/02

Dependencies: 76940

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSSv3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:f5:big-ip_access_policy_manager, cpe:/a:f5:big-ip_advanced_firewall_manager, cpe:/a:f5:big-ip_application_acceleration_manager, cpe:/a:f5:big-ip_application_security_manager, cpe:/a:f5:big-ip_application_visibility_and_reporting, cpe:/a:f5:big-ip_global_traffic_manager, cpe:/a:f5:big-ip_link_controller, cpe:/a:f5:big-ip_local_traffic_manager, cpe:/a:f5:big-ip_policy_enforcement_manager, cpe:/a:f5:big-ip_webaccelerator, cpe:/h:f5:big-ip, cpe:/h:f5:big-ip_protocol_security_manager

Required KB Items: Host/local_checks_enabled, Host/BIG-IP/hotfix, Host/BIG-IP/modules, Host/BIG-IP/version

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2017/05/08

Reference Information

CVE: CVE-2017-6462