CVE-2015-7703: Debian Linux
High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Netapp Clustered Data Ontap: affected versions not specified
- Netapp Data Ontap: affected versions not specified
- Netapp Oncommand Performance Manager: affected versions not specified
- Netapp Oncommand Unified Manager: affected versions not specified
- Ntp Ntp: from 4.2.0, before 4.2.8 (fixed in 4.2.8); from 4.3.0, before 4.3.77 (fixed in 4.3.77); version 4.2.8 only
- Oracle Linux: version 6 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Eus: version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Server Tus: version 7.3 only; version 7.6 only; version 7.7 only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
Published 2017-07-24. Last modified 2026-06-17.