PT-2001-1013 · Ntp+1 · Ntp+1

Published

2001-04-05

·

Updated

2017-10-10

·

CVE-2001-0414

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ntp versions 4.0.99k and earlier xntp3 versions prior to the fixed version
Description The issue allows remote attackers to cause a denial of service and possibly execute arbitrary commands, leading to a violation of confidentiality, integrity, and availability of protected information. This can be exploited remotely.
Recommendations For ntp versions 4.0.99k and earlier, update to a version later than 4.0.99k to resolve the issue. For xntp3 versions prior to the fixed version, update to the fixed version or later to mitigate the risk. As a temporary workaround, consider restricting access to the ntpd daemon to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03681
BDU:2015-07895
CVE-2001-0414

Affected Products

Ntp
Xntp3