PT-2009-1058 · Moxa+4 · Moxa Pt-7828+7
Dmitri Vinokurov
+1
·
Published
2009-12-08
·
Updated
2024-03-20
·
CVE-2009-3563
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Moxa PT-508, PT-7728, PT-7828, MDS-G4012 (affected versions not specified)
ntp versions prior to 4.2.4p8
ntp version 4.2.0.a.20040617
ntp version 4.1.2
Description
The issue is related to uncontrolled recursion in the Ethernet switch microcode and multiple vulnerabilities in the ntp package, which can lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely, allowing an attacker to cause a denial of service or disrupt the system. The vulnerability in ntpd allows remote attackers to cause a denial of service by sending spoofed request or response packets, triggering a continuous exchange of error responses between two NTP daemons.
Recommendations
For Moxa PT-508, PT-7728, PT-7828, MDS-G4012, restrict access to the vulnerable microcode to minimize the risk of exploitation until a patch is available.
For ntp versions prior to 4.2.4p8, update to version 4.2.4p8 or later to resolve the issue.
For ntp version 4.2.0.a.20040617 and ntp version 4.1.2, update to a newer version that contains a fix for this issue.
As a temporary workaround, consider disabling the
ntp request.c function in ntpd until a patch is available.Exploit
Fix
Buffer Overflow
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios
Hp-Ux
Moxa Mds-G4012
Moxa Pt-508
Moxa Pt-7728
Moxa Pt-7828
Red Hat
Ntp