U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2015-3405

Change History

Initial Analysis by NIST 8/25/2017 10:55:58 AM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:ntp:ntp:4.2.8:p1:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.2.8:p2:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.2.8:p2_rc1:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.0:*:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.1:*:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.2:*:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.3:*:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.4:*:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.5:*:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.6:*:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.7:*:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.8:*:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.9:*:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.10:*:*:*:*:*:*:*
     *cpe:2.3:a:ntp:ntp:4.3.11:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
     *cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:opensuse:suse_linux_enterprise_server:11.0:sp3:*:*:*:*:*:*
     *cpe:2.3:o:opensuse_project:suse_linux_enterprise_desktop:11.0:sp3:*:*:*:*:*:*
     *cpe:2.3:o:suse:suse_linux_enterprise_server:11.0:sp3:*:*:*:vmware:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_for_power_big_endian:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_for_scientific_computing:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_from_rhui_6:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Added CVSS V3

								
							
							
						
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Added CWE

								
							
							
						
CWE-331
Changed Reference Type
http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=55199296N2gFqH1Hm5GOnhrk9Ypygg No Types Assigned
http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=55199296N2gFqH1Hm5GOnhrk9Ypygg Third Party Advisory, Vendor Advisory
Changed Reference Type
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156248.html No Types Assigned
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/156248.html Third Party Advisory
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00000.html No Types Assigned
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00000.html Third Party Advisory
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2015-1459.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2015-1459.html Third Party Advisory, VDB Entry
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2015-2231.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2015-2231.html Third Party Advisory, VDB Entry
Changed Reference Type
http://www.debian.org/security/2015/dsa-3223 No Types Assigned
http://www.debian.org/security/2015/dsa-3223 Third Party Advisory
Changed Reference Type
http://www.debian.org/security/2015/dsa-3388 No Types Assigned
http://www.debian.org/security/2015/dsa-3388 Third Party Advisory
Changed Reference Type
http://www.openwall.com/lists/oss-security/2015/04/23/14 No Types Assigned
http://www.openwall.com/lists/oss-security/2015/04/23/14 Mailing List, Third Party Advisory
Changed Reference Type
http://www.securityfocus.com/bid/74045 No Types Assigned
http://www.securityfocus.com/bid/74045 Third Party Advisory, VDB Entry
Changed Reference Type
https://bugs.ntp.org/show_bug.cgi?id=2797 No Types Assigned
https://bugs.ntp.org/show_bug.cgi?id=2797 Issue Tracking, Third Party Advisory, Vendor Advisory
Changed Reference Type
https://bugzilla.redhat.com/show_bug.cgi?id=1210324 No Types Assigned
https://bugzilla.redhat.com/show_bug.cgi?id=1210324 Issue Tracking, Patch, Third Party Advisory, VDB Entry