PT-2009-1058 · Moxa+4 · Moxa Pt-7828+7

Dmitri Vinokurov

+1

·

Published

2009-12-08

·

Updated

2024-03-20

·

CVE-2009-3563

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Moxa PT-508, PT-7728, PT-7828, MDS-G4012 (affected versions not specified) ntp versions prior to 4.2.4p8 ntp version 4.2.0.a.20040617 ntp version 4.1.2
Description The issue is related to uncontrolled recursion in the Ethernet switch microcode and multiple vulnerabilities in the ntp package, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely, allowing an attacker to cause a denial of service or disrupt the system. The vulnerability in ntpd allows remote attackers to cause a denial of service by sending spoofed request or response packets, triggering a continuous exchange of error responses between two NTP daemons.
Recommendations For Moxa PT-508, PT-7728, PT-7828, MDS-G4012, restrict access to the vulnerable microcode to minimize the risk of exploitation until a patch is available. For ntp versions prior to 4.2.4p8, update to version 4.2.4p8 or later to resolve the issue. For ntp version 4.2.0.a.20040617 and ntp version 4.1.2, update to a newer version that contains a fix for this issue. As a temporary workaround, consider disabling the ntp request.c function in ntpd until a patch is available.

Exploit

Fix

Buffer Overflow

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

BDU:2015-06447
BDU:2015-07451
BDU:2015-08487
BDU:2015-08550
BDU:2015-09410
CVE-2009-3563
DSA-1948-1
HPSBUX02639
HPSBUX02859
RHSA-2009:1648
RHSA-2009:1651
RHSA-2009_1648

Affected Products

Cisco Ios
Hp-Ux
Moxa Mds-G4012
Moxa Pt-508
Moxa Pt-7728
Moxa Pt-7828
Red Hat
Ntp