Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-5146

16
FAUCET Score

CVE-2015-5146 describes a denial-of-service vulnerability in ntpd versions prior to 4.2.8p3, affecting various Debian and Fedora distributions. An authenticated attacker, possessing the configuration password and access to a trusted remote configuration computer, could crash the NTP service by sending a crafted configuration directive containing a NULL byte. This medium-severity vulnerability (CVSS 5.3) requires high attack complexity and low privileges, leading to a high availability impact. There is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
21CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
22CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
23CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.3MEDIUM

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.6
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
4.09%
Probability of exploitation in next 30 days
EPSS Percentile
89.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0410 is in the 94th percentile among its peer group of 1,425 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (3)

gentooworkaround availablevia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: ntp
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: ntp

Vendor Advisories (1)

redhatCVE-2015-5146Low

ntp: ntpd control message crash on crafted NUL-byte in configuration directive (VU#668167)

Jun 30, 2015

References

bugs.ntp.org / show_bug.cgi
Issue TrackingThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2015-November/170926.html
Third Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2015-October/169167.html
Third Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2015-September/166992.html
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
security.gentoo.org / glsa/201509-01
MitigationThird Party AdvisoryVDB Entry
security.netapp.com / advisory/ntap-20180731-0003
support.ntp.org / bin/view/Main/SecurityNotice
Vendor Advisory
debian.org / security/2015/dsa-3388
Third Party Advisory
securityfocus.com / bid/75589
Third Party AdvisoryVDB Entry
securitytracker.com / id/1034168
Third Party AdvisoryVDB Entry