// For flags

CVE-2009-1252

ntp: remote arbitrary code execution vulnerability if autokeys is enabled

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

Desbordamiento de búfer basado en pila en la función crypto_recv en ntp_crypto.c en ntpd en NTP anteriores a v4.2.4p7 y v4.2.5 anterior a v4.2.5p74, cuando OpenSSL y autokey están activados, permite a atacantes remotos ejecutar código de forma arbitraria a través de paquetes manipulados que contienen un campo de extension.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-04-07 CVE Reserved
  • 2009-05-19 CVE Published
  • 2024-07-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
  • CWE-121: Stack-based Buffer Overflow
CAPEC
References (40)
URL Tag Source
http://secunia.com/advisories/35137 Third Party Advisory
http://secunia.com/advisories/35138 Third Party Advisory
http://secunia.com/advisories/35166 Third Party Advisory
http://secunia.com/advisories/35169 Third Party Advisory
http://secunia.com/advisories/35243 Third Party Advisory
http://secunia.com/advisories/35253 Third Party Advisory
http://secunia.com/advisories/35308 Third Party Advisory
http://secunia.com/advisories/35336 Third Party Advisory
http://secunia.com/advisories/35388 Third Party Advisory
http://secunia.com/advisories/35416 Third Party Advisory
http://secunia.com/advisories/35630 Third Party Advisory
http://secunia.com/advisories/37470 Third Party Advisory
http://secunia.com/advisories/37471 Third Party Advisory
http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0092 X_refsource_confirm
http://www.kb.cert.org/vuls/id/853097 Third Party Advisory
http://www.securityfocus.com/archive/1/507985/100/0/threaded Mailing List
http://www.securityfocus.com/bid/35017 Vdb Entry
http://www.securitytracker.com/id?1022243 Vdb Entry
http://www.vmware.com/security/advisories/VMSA-2009-0016.html X_refsource_confirm
http://www.vupen.com/english/advisories/2009/1361 Vdb Entry
http://www.vupen.com/english/advisories/2009/3316 Vdb Entry
https://launchpad.net/bugs/cve/2009-1252 X_refsource_misc
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11231 Signature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6307 Signature
https://support.ntp.org/bugs/show_bug.cgi?id=1151 X_refsource_confirm
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p0
Search vendor "Ntp" for product "Ntp" and version "4.2.4p0"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p1
Search vendor "Ntp" for product "Ntp" and version "4.2.4p1"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p2
Search vendor "Ntp" for product "Ntp" and version "4.2.4p2"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p3
Search vendor "Ntp" for product "Ntp" and version "4.2.4p3"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p4
Search vendor "Ntp" for product "Ntp" and version "4.2.4p4"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p5
Search vendor "Ntp" for product "Ntp" and version "4.2.4p5"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p6
Search vendor "Ntp" for product "Ntp" and version "4.2.4p6"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p0
Search vendor "Ntp" for product "Ntp" and version "4.2.5p0"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p1
Search vendor "Ntp" for product "Ntp" and version "4.2.5p1"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p2
Search vendor "Ntp" for product "Ntp" and version "4.2.5p2"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p3
Search vendor "Ntp" for product "Ntp" and version "4.2.5p3"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p4
Search vendor "Ntp" for product "Ntp" and version "4.2.5p4"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p5
Search vendor "Ntp" for product "Ntp" and version "4.2.5p5"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p6
Search vendor "Ntp" for product "Ntp" and version "4.2.5p6"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p7
Search vendor "Ntp" for product "Ntp" and version "4.2.5p7"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p8
Search vendor "Ntp" for product "Ntp" and version "4.2.5p8"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p9
Search vendor "Ntp" for product "Ntp" and version "4.2.5p9"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p10
Search vendor "Ntp" for product "Ntp" and version "4.2.5p10"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p11
Search vendor "Ntp" for product "Ntp" and version "4.2.5p11"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p12
Search vendor "Ntp" for product "Ntp" and version "4.2.5p12"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p13
Search vendor "Ntp" for product "Ntp" and version "4.2.5p13"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p14
Search vendor "Ntp" for product "Ntp" and version "4.2.5p14"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p15
Search vendor "Ntp" for product "Ntp" and version "4.2.5p15"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p16
Search vendor "Ntp" for product "Ntp" and version "4.2.5p16"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p17
Search vendor "Ntp" for product "Ntp" and version "4.2.5p17"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p18
Search vendor "Ntp" for product "Ntp" and version "4.2.5p18"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p19
Search vendor "Ntp" for product "Ntp" and version "4.2.5p19"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p20
Search vendor "Ntp" for product "Ntp" and version "4.2.5p20"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p21
Search vendor "Ntp" for product "Ntp" and version "4.2.5p21"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p23
Search vendor "Ntp" for product "Ntp" and version "4.2.5p23"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p24
Search vendor "Ntp" for product "Ntp" and version "4.2.5p24"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p25
Search vendor "Ntp" for product "Ntp" and version "4.2.5p25"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p26
Search vendor "Ntp" for product "Ntp" and version "4.2.5p26"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p27
Search vendor "Ntp" for product "Ntp" and version "4.2.5p27"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p28
Search vendor "Ntp" for product "Ntp" and version "4.2.5p28"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p29
Search vendor "Ntp" for product "Ntp" and version "4.2.5p29"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p30
Search vendor "Ntp" for product "Ntp" and version "4.2.5p30"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p31
Search vendor "Ntp" for product "Ntp" and version "4.2.5p31"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p32
Search vendor "Ntp" for product "Ntp" and version "4.2.5p32"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p33
Search vendor "Ntp" for product "Ntp" and version "4.2.5p33"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p35
Search vendor "Ntp" for product "Ntp" and version "4.2.5p35"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p36
Search vendor "Ntp" for product "Ntp" and version "4.2.5p36"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p37
Search vendor "Ntp" for product "Ntp" and version "4.2.5p37"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p38
Search vendor "Ntp" for product "Ntp" and version "4.2.5p38"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p39
Search vendor "Ntp" for product "Ntp" and version "4.2.5p39"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p40
Search vendor "Ntp" for product "Ntp" and version "4.2.5p40"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p41
Search vendor "Ntp" for product "Ntp" and version "4.2.5p41"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p42
Search vendor "Ntp" for product "Ntp" and version "4.2.5p42"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p43
Search vendor "Ntp" for product "Ntp" and version "4.2.5p43"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p44
Search vendor "Ntp" for product "Ntp" and version "4.2.5p44"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p45
Search vendor "Ntp" for product "Ntp" and version "4.2.5p45"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p46
Search vendor "Ntp" for product "Ntp" and version "4.2.5p46"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p47
Search vendor "Ntp" for product "Ntp" and version "4.2.5p47"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p48
Search vendor "Ntp" for product "Ntp" and version "4.2.5p48"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p49
Search vendor "Ntp" for product "Ntp" and version "4.2.5p49"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p50
Search vendor "Ntp" for product "Ntp" and version "4.2.5p50"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p51
Search vendor "Ntp" for product "Ntp" and version "4.2.5p51"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p52
Search vendor "Ntp" for product "Ntp" and version "4.2.5p52"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p53
Search vendor "Ntp" for product "Ntp" and version "4.2.5p53"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p54
Search vendor "Ntp" for product "Ntp" and version "4.2.5p54"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p55
Search vendor "Ntp" for product "Ntp" and version "4.2.5p55"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p56
Search vendor "Ntp" for product "Ntp" and version "4.2.5p56"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p57
Search vendor "Ntp" for product "Ntp" and version "4.2.5p57"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p58
Search vendor "Ntp" for product "Ntp" and version "4.2.5p58"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p59
Search vendor "Ntp" for product "Ntp" and version "4.2.5p59"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p60
Search vendor "Ntp" for product "Ntp" and version "4.2.5p60"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p61
Search vendor "Ntp" for product "Ntp" and version "4.2.5p61"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p62
Search vendor "Ntp" for product "Ntp" and version "4.2.5p62"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p63
Search vendor "Ntp" for product "Ntp" and version "4.2.5p63"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p64
Search vendor "Ntp" for product "Ntp" and version "4.2.5p64"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p65
Search vendor "Ntp" for product "Ntp" and version "4.2.5p65"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p66
Search vendor "Ntp" for product "Ntp" and version "4.2.5p66"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p67
Search vendor "Ntp" for product "Ntp" and version "4.2.5p67"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p68
Search vendor "Ntp" for product "Ntp" and version "4.2.5p68"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p69
Search vendor "Ntp" for product "Ntp" and version "4.2.5p69"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p70
Search vendor "Ntp" for product "Ntp" and version "4.2.5p70"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p71
Search vendor "Ntp" for product "Ntp" and version "4.2.5p71"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p73
Search vendor "Ntp" for product "Ntp" and version "4.2.5p73"
-
Affected