CVE-2015-5195: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 8.8% chance of exploitation in the next 30 days.

ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Fedoraproject Fedora: version 21 only; version 22 only; version 23 only
  • Ntp Ntp: up to and including 4.2.7
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Hpc Node: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only

Published 2017-07-21. Last modified 2026-06-17.