PT-2009-6682 · Openssl+2 · Openssl+2

Chris Ries

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-1252

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ntp versions prior to 4.2.4p7 ntp versions prior to 4.2.5p74
Description The issue concerns multiple vulnerabilities in the ntp package, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A specific vulnerability is a stack-based buffer overflow in the crypto recv function in ntpd, which allows remote attackers to execute arbitrary code via a crafted packet containing an extension field when OpenSSL and autokey are enabled.
Recommendations For ntp versions prior to 4.2.4p7, update to version 4.2.4p7 or later to resolve the issue. For ntp versions prior to 4.2.5p74, update to version 4.2.5p74 or later to resolve the issue. As a temporary workaround, consider disabling the crypto recv function until a patch is available. Restrict access to the ntp service to minimize the risk of exploitation.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02159
BDU:2015-02160
BDU:2015-02161
BDU:2015-02162
BDU:2015-02163
BDU:2015-06448
BDU:2015-08486
BDU:2015-09376
CVE-2009-1252
DSA-1801-1
OPENSUSE-SU-2024:10181-1
RHSA-2009:1039
RHSA-2009:1040
RHSA-2009_1039
RHSA-2009_1040

Affected Products

Openssl
Red Hat
Ntp