5

CVE-2013-5211

The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opensuse ≫ Opensuse Version 11.4
Ntp ≫ Ntp Version < 4.2.7
Ntp ≫ Ntp Version 4.2.7 Update -
Ntp ≫ Ntp Version 4.2.7 Update p0
Ntp ≫ Ntp Version 4.2.7 Update p1
Ntp ≫ Ntp Version 4.2.7 Update p10
Ntp ≫ Ntp Version 4.2.7 Update p11
Ntp ≫ Ntp Version 4.2.7 Update p12
Ntp ≫ Ntp Version 4.2.7 Update p13
Ntp ≫ Ntp Version 4.2.7 Update p14
Ntp ≫ Ntp Version 4.2.7 Update p15
Ntp ≫ Ntp Version 4.2.7 Update p16
Ntp ≫ Ntp Version 4.2.7 Update p17
Ntp ≫ Ntp Version 4.2.7 Update p18
Ntp ≫ Ntp Version 4.2.7 Update p19
Ntp ≫ Ntp Version 4.2.7 Update p2
Ntp ≫ Ntp Version 4.2.7 Update p20
Ntp ≫ Ntp Version 4.2.7 Update p21
Ntp ≫ Ntp Version 4.2.7 Update p22
Ntp ≫ Ntp Version 4.2.7 Update p23
Ntp ≫ Ntp Version 4.2.7 Update p24
Ntp ≫ Ntp Version 4.2.7 Update p25
Ntp ≫ Ntp Version 4.2.7 Update p3
Ntp ≫ Ntp Version 4.2.7 Update p4
Ntp ≫ Ntp Version 4.2.7 Update p5
Ntp ≫ Ntp Version 4.2.7 Update p6
Ntp ≫ Ntp Version 4.2.7 Update p7
Ntp ≫ Ntp Version 4.2.7 Update p8
Ntp ≫ Ntp Version 4.2.7 Update p9
Oracle ≫ Linux Version 6 Update -
Oracle ≫ Linux Version 7 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 97.55% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://aix.software.ibm.com/aix/efixes/security/ntp_advisory.asc
Third Party Advisory
http://bugs.ntp.org/show_bug.cgi?id=1532
Issue Tracking
http://ics-cert.us-cert.gov/advisories/ICSA-14-051-04
Third Party Advisory
US Government Resource
http://lists.ntp.org/pipermail/pool/2011-December/005616.html
Broken Link
http://lists.opensuse.org/opensuse-updates/2014-09/msg00031.html
Third Party Advisory
http://marc.info/?l=bugtraq&m=138971294629419&w=2
Mailing List
http://marc.info/?l=bugtraq&m=144182594518755&w=2
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2013/12/30/6
Mailing List
http://openwall.com/lists/oss-security/2013/12/30/7
Mailing List
http://secunia.com/advisories/59288
Not Applicable
http://secunia.com/advisories/59726
Not Applicable
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095861
Broken Link
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095892
Broken Link
http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-dev/ntp-dev-4.2.7p26.tar.gz
Patch
http://www.kb.cert.org/vuls/id/348126
Third Party Advisory
US Government Resource
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
Third Party Advisory
http://www.securityfocus.com/bid/64692
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1030433
Third Party Advisory
VDB Entry
http://www.us-cert.gov/ncas/alerts/TA14-013A
Third Party Advisory
US Government Resource
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04790232
Third Party Advisory
https://puppet.com/security/cve/puppetlabs-ntp-nov-2015-advisory
Broken Link