CVE-2015-7975: Ntp
Medium severity, CVSS 6.2. EPSS: 0.6% chance of exploitation in the next 30 days.
The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, which allows an attacker to cause a denial of service (application crash).
Affected products
- Ntp Ntp: up to and including 4.2.8; version 4.3.0 only; version 4.3.1 only; version 4.3.2 only; version 4.3.3 only; version 4.3.4 only; …
Published 2017-01-30. Last modified 2026-06-17.