6.8

CVE-2009-1252

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

Data is provided by the National Vulnerability Database (NVD)
NtpNtp Version4.2.4p0
NtpNtp Version4.2.4p1
NtpNtp Version4.2.4p2
NtpNtp Version4.2.4p3
NtpNtp Version4.2.4p4
NtpNtp Version4.2.4p5
NtpNtp Version4.2.4p6
NtpNtp Version4.2.5p0
NtpNtp Version4.2.5p1
NtpNtp Version4.2.5p2
NtpNtp Version4.2.5p3
NtpNtp Version4.2.5p4
NtpNtp Version4.2.5p5
NtpNtp Version4.2.5p6
NtpNtp Version4.2.5p7
NtpNtp Version4.2.5p8
NtpNtp Version4.2.5p9
NtpNtp Version4.2.5p10
NtpNtp Version4.2.5p11
NtpNtp Version4.2.5p12
NtpNtp Version4.2.5p13
NtpNtp Version4.2.5p14
NtpNtp Version4.2.5p15
NtpNtp Version4.2.5p16
NtpNtp Version4.2.5p17
NtpNtp Version4.2.5p18
NtpNtp Version4.2.5p19
NtpNtp Version4.2.5p20
NtpNtp Version4.2.5p21
NtpNtp Version4.2.5p23
NtpNtp Version4.2.5p24
NtpNtp Version4.2.5p25
NtpNtp Version4.2.5p26
NtpNtp Version4.2.5p27
NtpNtp Version4.2.5p28
NtpNtp Version4.2.5p29
NtpNtp Version4.2.5p30
NtpNtp Version4.2.5p31
NtpNtp Version4.2.5p32
NtpNtp Version4.2.5p33
NtpNtp Version4.2.5p35
NtpNtp Version4.2.5p36
NtpNtp Version4.2.5p37
NtpNtp Version4.2.5p38
NtpNtp Version4.2.5p39
NtpNtp Version4.2.5p40
NtpNtp Version4.2.5p41
NtpNtp Version4.2.5p42
NtpNtp Version4.2.5p43
NtpNtp Version4.2.5p44
NtpNtp Version4.2.5p45
NtpNtp Version4.2.5p46
NtpNtp Version4.2.5p47
NtpNtp Version4.2.5p48
NtpNtp Version4.2.5p49
NtpNtp Version4.2.5p50
NtpNtp Version4.2.5p51
NtpNtp Version4.2.5p52
NtpNtp Version4.2.5p53
NtpNtp Version4.2.5p54
NtpNtp Version4.2.5p55
NtpNtp Version4.2.5p56
NtpNtp Version4.2.5p57
NtpNtp Version4.2.5p58
NtpNtp Version4.2.5p59
NtpNtp Version4.2.5p60
NtpNtp Version4.2.5p61
NtpNtp Version4.2.5p62
NtpNtp Version4.2.5p63
NtpNtp Version4.2.5p64
NtpNtp Version4.2.5p65
NtpNtp Version4.2.5p66
NtpNtp Version4.2.5p67
NtpNtp Version4.2.5p68
NtpNtp Version4.2.5p69
NtpNtp Version4.2.5p70
NtpNtp Version4.2.5p71
NtpNtp Version4.2.5p73
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 47.1% 0.976
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.