Lucene search

K
f5F5F5:K15928
HistoryDec 23, 2014 - 12:00 a.m.

K15928 : Network Time Protocol vulnerability CVE-2009-1252

2014-12-2300:00:00
my.f5.com
11

8 High

AI Score

Confidence

High

0.963 High

EPSS

Percentile

99.5%

Security Advisory Description

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.
(
CVE-2009-1252
)
Impact
None. Authentication is not enabled in the default NTP configuration for F5 products.