PT-2017-17081 · Ntt+4 · Ntp+4

Published

2017-03-27

·

Updated

2024-06-15

·

CVE-2017-6458

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NTP versions prior to 4.2.8p10 NTP versions 4.3.x prior to 4.3.94
Description The issue is related to multiple buffer overflows in the ctl put* functions, allowing remote authenticated users to have an unspecified impact via a long variable. Additionally, a denial of service vulnerability exists, where a remote authenticated attacker could exploit this using a malformed mode configuration directive to cause the application to crash.
Recommendations For NTP versions prior to 4.2.8p10, update to version 4.2.8p10 or later. For NTP versions 4.3.x prior to 4.3.94, update to version 4.3.94 or later.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2335
CVE-2017-6458
MGASA-2017-0134
OPENSUSE-SU-2024:11102-1
SUSE-SU-2017:1047-1
SUSE-SU-2017:1048-1
SUSE-SU-2017:1052-1
USN-3349-1

Affected Products

Alt Linux
Ibm Aix
Ntp
Suse
Ubuntu