NTP BUG 2669: Buffer overflow in configure()

Last update: June 28, 2022 20:06 UTC (57417e17c)


Summary

Resolved 4.2.8 18 Dec 2014
References Bug 2669 CVE-2014-9295
Affects All NTP4 releases before 4.2.8. Resolved in 4.2.8.
CVSS2 Score 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

A remote attacker can send a carefully crafted packet that can overflow a stack buffer and potentially allow malicious code to be executed with the privilege level of the ntpd process.


Mitigation

Any of:


Credit

This vulnerability was discovered by Stephen Roettger of the Google Security Team.


Timeline