NTP BUG 2668: Buffer overflow in ctl_putdata()

Last update: February 15, 2022 15:25 UTC (b158e7036)


Summary

Resolved 4.2.8 18 Dec 2014
References Bug 2668 CVE-2014-9295
Affects All NTP4 releases before 4.2.8. Resolved in 4.2.8.
CVSS2 Score 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

A remote attacker can send a carefully crafted packet that can overflow a stack buffer and potentially allow malicious code to be executed with the privilege level of the ntpd process.


Mitigation

Any of:


Credit

This vulnerability was discovered by Stephen Roettger of the Google Security Team.


Timeline