The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 16.04 LTS allows local users with access to the ntp account to write to arbitrary files and consequently gain privileges via vectors involving statistics directory cleanup.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.ubuntu.com/usn/USN-3096-1 | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1382369 | issue tracking |
http://www.securitytracker.com/id/1034808 | vdb entry third party advisory |
http://packetstormsecurity.com/files/141913/NTP-Privilege-Escalation.html | exploit vdb entry third party advisory |
http://www.securityfocus.com/bid/81552 | vdb entry third party advisory |
https://bugs.launchpad.net/ubuntu/+source/ntp/+bug/1528050 | issue tracking patch vendor advisory |