CVE-2015-7977: Canonical Ubuntu Linux
Medium severity, CVSS 5.9. EPSS: 6.3% chance of exploitation in the next 30 days.
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Fedoraproject Fedora: version 22 only; version 23 only
- Freebsd Freebsd: version 9.3 only; version 10.1 only; version 10.2 only
- Netapp Clustered Data Ontap: affected versions not specified
- Netapp Oncommand Balance: affected versions not specified
- Ntp Ntp: up to and including 4.2.8; from 4.3.0, before 4.3.90 (fixed in 4.3.90); version 4.2.8 only
- Oracle Linux: version 6 only
- Siemens Tim 4r-Ie DNP3 Firmware: affected versions not specified
- Siemens Tim 4r-Ie Firmware: any version
Published 2017-01-30. Last modified 2026-06-17.