Multiple bugs in cronjob script bundled with ntp package were found allowing malicious ntp user to make the backup process to overwrite arbitrary files with content controlled by the attacker, thus gaining root privileges. External References: http://www.halfdog.net/Security/2015/NtpCronjobUserNtpToRootPrivilegeEscalation/
Created ntp tracking bugs for this issue: Affects: fedora-all [bug 1382370]
Statement: This issue did not affect the versions of ntp as shipped with Red Hat Enterprise Linux 5, 6, or 7.