5

CVE-2013-5211

The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpensuseOpensuse Version11.4
NtpNtp Version < 4.2.7
NtpNtp Version4.2.7 Update-
NtpNtp Version4.2.7 Updatep0
NtpNtp Version4.2.7 Updatep1
NtpNtp Version4.2.7 Updatep10
NtpNtp Version4.2.7 Updatep11
NtpNtp Version4.2.7 Updatep12
NtpNtp Version4.2.7 Updatep13
NtpNtp Version4.2.7 Updatep14
NtpNtp Version4.2.7 Updatep15
NtpNtp Version4.2.7 Updatep16
NtpNtp Version4.2.7 Updatep17
NtpNtp Version4.2.7 Updatep18
NtpNtp Version4.2.7 Updatep19
NtpNtp Version4.2.7 Updatep2
NtpNtp Version4.2.7 Updatep20
NtpNtp Version4.2.7 Updatep21
NtpNtp Version4.2.7 Updatep22
NtpNtp Version4.2.7 Updatep23
NtpNtp Version4.2.7 Updatep24
NtpNtp Version4.2.7 Updatep25
NtpNtp Version4.2.7 Updatep3
NtpNtp Version4.2.7 Updatep4
NtpNtp Version4.2.7 Updatep5
NtpNtp Version4.2.7 Updatep6
NtpNtp Version4.2.7 Updatep7
NtpNtp Version4.2.7 Updatep8
NtpNtp Version4.2.7 Updatep9
OracleLinux Version6 Update-
OracleLinux Version7 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 91.73% 0.997
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://ics-cert.us-cert.gov/advisories/ICSA-14-051-04
Third Party Advisory
US Government Resource
http://marc.info/?l=bugtraq&m=144182594518755&w=2
Third Party Advisory
Mailing List
http://www.kb.cert.org/vuls/id/348126
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/64692
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1030433
Third Party Advisory
VDB Entry
http://www.us-cert.gov/ncas/alerts/TA14-013A
Third Party Advisory
US Government Resource