Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.
| Software | From | Fixed in |
|---|---|---|
| ntp / ntp | 4.2.8-p2 | 4.2.8-p2.x |
| ntp / ntp | 4.2.8-p3 | 4.2.8-p3.x |
| ntp / ntp | 4.2.8-p1 | 4.2.8-p1.x |
| ntp / ntp | 4.2.8-p3-rc3 | 4.2.8-p3-rc3.x |
| ntp / ntp | 4.2.8-p3-rc2 | 4.2.8-p3-rc2.x |
| ntp / ntp | 4.2.8-p3-rc1 | 4.2.8-p3-rc1.x |
| ntp / ntp | 4.2.8-p2-rc3 | 4.2.8-p2-rc3.x |
| ntp / ntp | 4.2.8-p2-rc2 | 4.2.8-p2-rc2.x |
| ntp / ntp | 4.2.8-p2-rc1 | 4.2.8-p2-rc1.x |
| ntp / ntp | 4.2.8-p1-rc2 | 4.2.8-p1-rc2.x |
| ntp / ntp | 4.2.8-p1-rc1 | 4.2.8-p1-rc1.x |
| ntp / ntp | 4.2.8-p1-beta5 | 4.2.8-p1-beta5.x |
| ntp / ntp | 4.2.8-p1-beta4 | 4.2.8-p1-beta4.x |
| ntp / ntp | 4.2.8-p1-beta3 | 4.2.8-p1-beta3.x |
| ntp / ntp | 4.2.8-p1-beta2 | 4.2.8-p1-beta2.x |
| ntp / ntp | 4.2.8-p1-beta1 | 4.2.8-p1-beta1.x |
| ntp / ntp | 4.3.0 | 4.3.77 |
| ntp / ntp | 4.2.0 | 4.2.8 |