Lucene search

K
nvd[email protected]NVD:CVE-2009-1252
HistoryMay 19, 2009 - 7:30 p.m.

CVE-2009-1252

2009-05-1919:30:00
CWE-119
web.nvd.nist.gov
1

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.9 High

AI Score

Confidence

High

0.963 High

EPSS

Percentile

99.5%

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

Affected configurations

NVD
Node
ntpntpMatch4.2.4p0
OR
ntpntpMatch4.2.4p1
OR
ntpntpMatch4.2.4p2
OR
ntpntpMatch4.2.4p3
OR
ntpntpMatch4.2.4p4
OR
ntpntpMatch4.2.4p5
OR
ntpntpMatch4.2.4p6
OR
ntpntpMatch4.2.5p0
OR
ntpntpMatch4.2.5p1
OR
ntpntpMatch4.2.5p2
OR
ntpntpMatch4.2.5p3
OR
ntpntpMatch4.2.5p4
OR
ntpntpMatch4.2.5p5
OR
ntpntpMatch4.2.5p6
OR
ntpntpMatch4.2.5p7
OR
ntpntpMatch4.2.5p8
OR
ntpntpMatch4.2.5p9
OR
ntpntpMatch4.2.5p10
OR
ntpntpMatch4.2.5p11
OR
ntpntpMatch4.2.5p12
OR
ntpntpMatch4.2.5p13
OR
ntpntpMatch4.2.5p14
OR
ntpntpMatch4.2.5p15
OR
ntpntpMatch4.2.5p16
OR
ntpntpMatch4.2.5p17
OR
ntpntpMatch4.2.5p18
OR
ntpntpMatch4.2.5p19
OR
ntpntpMatch4.2.5p20
OR
ntpntpMatch4.2.5p21
OR
ntpntpMatch4.2.5p23
OR
ntpntpMatch4.2.5p24
OR
ntpntpMatch4.2.5p25
OR
ntpntpMatch4.2.5p26
OR
ntpntpMatch4.2.5p27
OR
ntpntpMatch4.2.5p28
OR
ntpntpMatch4.2.5p29
OR
ntpntpMatch4.2.5p30
OR
ntpntpMatch4.2.5p31
OR
ntpntpMatch4.2.5p32
OR
ntpntpMatch4.2.5p33
OR
ntpntpMatch4.2.5p35
OR
ntpntpMatch4.2.5p36
OR
ntpntpMatch4.2.5p37
OR
ntpntpMatch4.2.5p38
OR
ntpntpMatch4.2.5p39
OR
ntpntpMatch4.2.5p40
OR
ntpntpMatch4.2.5p41
OR
ntpntpMatch4.2.5p42
OR
ntpntpMatch4.2.5p43
OR
ntpntpMatch4.2.5p44
OR
ntpntpMatch4.2.5p45
OR
ntpntpMatch4.2.5p46
OR
ntpntpMatch4.2.5p47
OR
ntpntpMatch4.2.5p48
OR
ntpntpMatch4.2.5p49
OR
ntpntpMatch4.2.5p50
OR
ntpntpMatch4.2.5p51
OR
ntpntpMatch4.2.5p52
OR
ntpntpMatch4.2.5p53
OR
ntpntpMatch4.2.5p54
OR
ntpntpMatch4.2.5p55
OR
ntpntpMatch4.2.5p56
OR
ntpntpMatch4.2.5p57
OR
ntpntpMatch4.2.5p58
OR
ntpntpMatch4.2.5p59
OR
ntpntpMatch4.2.5p60
OR
ntpntpMatch4.2.5p61
OR
ntpntpMatch4.2.5p62
OR
ntpntpMatch4.2.5p63
OR
ntpntpMatch4.2.5p64
OR
ntpntpMatch4.2.5p65
OR
ntpntpMatch4.2.5p66
OR
ntpntpMatch4.2.5p67
OR
ntpntpMatch4.2.5p68
OR
ntpntpMatch4.2.5p69
OR
ntpntpMatch4.2.5p70
OR
ntpntpMatch4.2.5p71
OR
ntpntpMatch4.2.5p73

References

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.9 High

AI Score

Confidence

High

0.963 High

EPSS

Percentile

99.5%