CVE-2015-7851: Ntp
Medium severity, CVSS 6.5. EPSS: 3.9% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.
Affected products
- Ntp Ntp: from 4.2.0, before 4.2.8 (fixed in 4.2.8); from 4.3.0, before 4.3.77 (fixed in 4.3.77); version 4.2.8 only
Published 2020-01-28. Last modified 2026-06-17.