PT-2001-1013 · Ntp+1 · Ntp+1
Publicado
2001-04-05
·
Atualizado
2017-10-10
·
CVE-2001-0414
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ntp versions 4.0.99k and earlier
xntp3 versions prior to the fixed version
Description
The issue allows remote attackers to cause a denial of service and possibly execute arbitrary commands, leading to a violation of confidentiality, integrity, and availability of protected information. This can be exploited remotely.
Recommendations
For ntp versions 4.0.99k and earlier, update to a version later than 4.0.99k to resolve the issue.
For xntp3 versions prior to the fixed version, update to the fixed version or later to mitigate the risk.
As a temporary workaround, consider restricting access to the
ntpd daemon to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ntp
Xntp3