CVE-2009-0021
ntp incorrectly checks for malformed signatures
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
NTP versiones 4.2.4 anteriores a 4.2.4p5 y versiones 4.2.5 anteriores a 4.2.5p150, no comprueba apropiadamente el valor devuelto de la funciĆ³n EVP_VerifyFinal de OpenSSL, que permite a los atacantes remotos omitir la comprobaciĆ³n de la cadena de certificados por medio de una firma de SSL/TLS malformada para las claves DSA y ECDSA, una vulnerabilidad similar a CVE-2008-5077.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-12-15 CVE Reserved
- 2009-01-07 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (21)
URL | Tag | Source |
---|---|---|
http://support.apple.com/kb/HT3549 | X_refsource_confirm | |
http://www.ocert.org/advisories/ocert-2008-016.html | X_refsource_misc | |
http://www.securityfocus.com/archive/1/499827/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1021533 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA09-133A.html | Third Party Advisory | |
https://lists.ntp.org/pipermail/announce/2009-January/000055.html | Mailing List | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10035 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | <= 4.2.4p4 Search vendor "Ntp" for product "Ntp" and version " <= 4.2.4p4" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.2.0 Search vendor "Ntp" for product "Ntp" and version "4.2.0" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.2.2 Search vendor "Ntp" for product "Ntp" and version "4.2.2" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.2.4p1 Search vendor "Ntp" for product "Ntp" and version "4.2.4p1" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.2.4p2 Search vendor "Ntp" for product "Ntp" and version "4.2.4p2" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.2.4p3 Search vendor "Ntp" for product "Ntp" and version "4.2.4p3" | - |
Affected
|