Lucene search

K
cve[email protected]CVE-2009-0159
HistoryApr 14, 2009 - 3:30 p.m.

CVE-2009-0159

2009-04-1415:30:00
CWE-119
web.nvd.nist.gov
67
cve-2009-0159
ntp
buffer overflow
remote code execution
security vulnerability

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.043 Low

EPSS

Percentile

92.4%

Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.

Affected configurations

NVD
Node
ntpntpRange4.2.4p7rc1
OR
ntpntpMatch4.0.72
OR
ntpntpMatch4.0.73
OR
ntpntpMatch4.0.90
OR
ntpntpMatch4.0.91
OR
ntpntpMatch4.0.92
OR
ntpntpMatch4.0.93
OR
ntpntpMatch4.0.94
OR
ntpntpMatch4.0.95
OR
ntpntpMatch4.0.96
OR
ntpntpMatch4.0.97
OR
ntpntpMatch4.0.98
OR
ntpntpMatch4.0.99
OR
ntpntpMatch4.1.0
OR
ntpntpMatch4.1.2
OR
ntpntpMatch4.2.0
OR
ntpntpMatch4.2.2
OR
ntpntpMatch4.2.2p1
OR
ntpntpMatch4.2.2p2
OR
ntpntpMatch4.2.2p3
OR
ntpntpMatch4.2.2p4
OR
ntpntpMatch4.2.4
OR
ntpntpMatch4.2.4p0
OR
ntpntpMatch4.2.4p1
OR
ntpntpMatch4.2.4p2
OR
ntpntpMatch4.2.4p3
OR
ntpntpMatch4.2.4p4
OR
ntpntpMatch4.2.4p5
OR
ntpntpMatch4.2.4p6

References

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.043 Low

EPSS

Percentile

92.4%