// For flags

CVE-2009-1252

ntp: remote arbitrary code execution vulnerability if autokeys is enabled

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

Desbordamiento de búfer basado en pila en la función crypto_recv en ntp_crypto.c en ntpd en NTP anteriores a v4.2.4p7 y v4.2.5 anterior a v4.2.5p74, cuando OpenSSL y autokey están activados, permite a atacantes remotos ejecutar código de forma arbitraria a través de paquetes manipulados que contienen un campo de extension.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-04-07 CVE Reserved
  • 2009-05-19 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
  • CWE-121: Stack-based Buffer Overflow
CAPEC
References (40)
URL Tag Source
http://secunia.com/advisories/35137 Third Party Advisory
http://secunia.com/advisories/35138 Third Party Advisory
http://secunia.com/advisories/35166 Third Party Advisory
http://secunia.com/advisories/35169 Third Party Advisory
http://secunia.com/advisories/35243 Third Party Advisory
http://secunia.com/advisories/35253 Third Party Advisory
http://secunia.com/advisories/35308 Third Party Advisory
http://secunia.com/advisories/35336 Third Party Advisory
http://secunia.com/advisories/35388 Third Party Advisory
http://secunia.com/advisories/35416 Third Party Advisory
http://secunia.com/advisories/35630 Third Party Advisory
http://secunia.com/advisories/37470 Third Party Advisory
http://secunia.com/advisories/37471 Third Party Advisory
http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0092 X_refsource_confirm
http://www.kb.cert.org/vuls/id/853097 Third Party Advisory
http://www.securityfocus.com/archive/1/507985/100/0/threaded Mailing List
http://www.securityfocus.com/bid/35017 Vdb Entry
http://www.securitytracker.com/id?1022243 Vdb Entry
http://www.vmware.com/security/advisories/VMSA-2009-0016.html X_refsource_confirm
http://www.vupen.com/english/advisories/2009/1361 Vdb Entry
http://www.vupen.com/english/advisories/2009/3316 Vdb Entry
https://launchpad.net/bugs/cve/2009-1252 X_refsource_misc
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11231 Signature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6307 Signature
https://support.ntp.org/bugs/show_bug.cgi?id=1151 X_refsource_confirm
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p0
Search vendor "Ntp" for product "Ntp" and version "4.2.4p0"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p1
Search vendor "Ntp" for product "Ntp" and version "4.2.4p1"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p2
Search vendor "Ntp" for product "Ntp" and version "4.2.4p2"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p3
Search vendor "Ntp" for product "Ntp" and version "4.2.4p3"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p4
Search vendor "Ntp" for product "Ntp" and version "4.2.4p4"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p5
Search vendor "Ntp" for product "Ntp" and version "4.2.4p5"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.4p6
Search vendor "Ntp" for product "Ntp" and version "4.2.4p6"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p0
Search vendor "Ntp" for product "Ntp" and version "4.2.5p0"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p1
Search vendor "Ntp" for product "Ntp" and version "4.2.5p1"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p2
Search vendor "Ntp" for product "Ntp" and version "4.2.5p2"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p3
Search vendor "Ntp" for product "Ntp" and version "4.2.5p3"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p4
Search vendor "Ntp" for product "Ntp" and version "4.2.5p4"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p5
Search vendor "Ntp" for product "Ntp" and version "4.2.5p5"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p6
Search vendor "Ntp" for product "Ntp" and version "4.2.5p6"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p7
Search vendor "Ntp" for product "Ntp" and version "4.2.5p7"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p8
Search vendor "Ntp" for product "Ntp" and version "4.2.5p8"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p9
Search vendor "Ntp" for product "Ntp" and version "4.2.5p9"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p10
Search vendor "Ntp" for product "Ntp" and version "4.2.5p10"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p11
Search vendor "Ntp" for product "Ntp" and version "4.2.5p11"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p12
Search vendor "Ntp" for product "Ntp" and version "4.2.5p12"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p13
Search vendor "Ntp" for product "Ntp" and version "4.2.5p13"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p14
Search vendor "Ntp" for product "Ntp" and version "4.2.5p14"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p15
Search vendor "Ntp" for product "Ntp" and version "4.2.5p15"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p16
Search vendor "Ntp" for product "Ntp" and version "4.2.5p16"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p17
Search vendor "Ntp" for product "Ntp" and version "4.2.5p17"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p18
Search vendor "Ntp" for product "Ntp" and version "4.2.5p18"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p19
Search vendor "Ntp" for product "Ntp" and version "4.2.5p19"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p20
Search vendor "Ntp" for product "Ntp" and version "4.2.5p20"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p21
Search vendor "Ntp" for product "Ntp" and version "4.2.5p21"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p23
Search vendor "Ntp" for product "Ntp" and version "4.2.5p23"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p24
Search vendor "Ntp" for product "Ntp" and version "4.2.5p24"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p25
Search vendor "Ntp" for product "Ntp" and version "4.2.5p25"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p26
Search vendor "Ntp" for product "Ntp" and version "4.2.5p26"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p27
Search vendor "Ntp" for product "Ntp" and version "4.2.5p27"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p28
Search vendor "Ntp" for product "Ntp" and version "4.2.5p28"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p29
Search vendor "Ntp" for product "Ntp" and version "4.2.5p29"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p30
Search vendor "Ntp" for product "Ntp" and version "4.2.5p30"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p31
Search vendor "Ntp" for product "Ntp" and version "4.2.5p31"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p32
Search vendor "Ntp" for product "Ntp" and version "4.2.5p32"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p33
Search vendor "Ntp" for product "Ntp" and version "4.2.5p33"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p35
Search vendor "Ntp" for product "Ntp" and version "4.2.5p35"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p36
Search vendor "Ntp" for product "Ntp" and version "4.2.5p36"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p37
Search vendor "Ntp" for product "Ntp" and version "4.2.5p37"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p38
Search vendor "Ntp" for product "Ntp" and version "4.2.5p38"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p39
Search vendor "Ntp" for product "Ntp" and version "4.2.5p39"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p40
Search vendor "Ntp" for product "Ntp" and version "4.2.5p40"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p41
Search vendor "Ntp" for product "Ntp" and version "4.2.5p41"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p42
Search vendor "Ntp" for product "Ntp" and version "4.2.5p42"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p43
Search vendor "Ntp" for product "Ntp" and version "4.2.5p43"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p44
Search vendor "Ntp" for product "Ntp" and version "4.2.5p44"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p45
Search vendor "Ntp" for product "Ntp" and version "4.2.5p45"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p46
Search vendor "Ntp" for product "Ntp" and version "4.2.5p46"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p47
Search vendor "Ntp" for product "Ntp" and version "4.2.5p47"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p48
Search vendor "Ntp" for product "Ntp" and version "4.2.5p48"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p49
Search vendor "Ntp" for product "Ntp" and version "4.2.5p49"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p50
Search vendor "Ntp" for product "Ntp" and version "4.2.5p50"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p51
Search vendor "Ntp" for product "Ntp" and version "4.2.5p51"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p52
Search vendor "Ntp" for product "Ntp" and version "4.2.5p52"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p53
Search vendor "Ntp" for product "Ntp" and version "4.2.5p53"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p54
Search vendor "Ntp" for product "Ntp" and version "4.2.5p54"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p55
Search vendor "Ntp" for product "Ntp" and version "4.2.5p55"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p56
Search vendor "Ntp" for product "Ntp" and version "4.2.5p56"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p57
Search vendor "Ntp" for product "Ntp" and version "4.2.5p57"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p58
Search vendor "Ntp" for product "Ntp" and version "4.2.5p58"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p59
Search vendor "Ntp" for product "Ntp" and version "4.2.5p59"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p60
Search vendor "Ntp" for product "Ntp" and version "4.2.5p60"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p61
Search vendor "Ntp" for product "Ntp" and version "4.2.5p61"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p62
Search vendor "Ntp" for product "Ntp" and version "4.2.5p62"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p63
Search vendor "Ntp" for product "Ntp" and version "4.2.5p63"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p64
Search vendor "Ntp" for product "Ntp" and version "4.2.5p64"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p65
Search vendor "Ntp" for product "Ntp" and version "4.2.5p65"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p66
Search vendor "Ntp" for product "Ntp" and version "4.2.5p66"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p67
Search vendor "Ntp" for product "Ntp" and version "4.2.5p67"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p68
Search vendor "Ntp" for product "Ntp" and version "4.2.5p68"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p69
Search vendor "Ntp" for product "Ntp" and version "4.2.5p69"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p70
Search vendor "Ntp" for product "Ntp" and version "4.2.5p70"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p71
Search vendor "Ntp" for product "Ntp" and version "4.2.5p71"
-
Affected
Ntp
Search vendor "Ntp"
Ntp
Search vendor "Ntp" for product "Ntp"
4.2.5p73
Search vendor "Ntp" for product "Ntp" and version "4.2.5p73"
-
Affected