CVE-2015-7973: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 3.4% chance of exploitation in the next 30 days.

NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only
  • Freebsd Freebsd: from 10.0, before 10.1 (fixed in 10.1); version 9.3 only; version 10.1 only; version 10.2 only
  • Netapp Clustered Data Ontap: affected versions not specified
  • Netapp Oncommand Balance: affected versions not specified
  • Ntp Ntp: before 4.2.8 (fixed in 4.2.8); from 4.3.0, before 4.3.90 (fixed in 4.3.90); version 4.2.8 only
  • Siemens Tim 4r-Ie DNP3 Firmware: any version
  • Siemens Tim 4r-Ie Firmware: any version

Published 2017-01-30. Last modified 2026-06-17.