CVE-2009-1252
Published May 19, 2009
Last updated 6 years ago
Overview
- Description
- Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-119
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ntp:ntp:4.2.4p0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA843BCD-372A-42F5-A8C0-1AD32FA9E94C" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.4p1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B980A178-2958-4B36-8AD8-3932B12C5A72" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.4p2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D65210A-F80E-4019-91DA-49838369E03F" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.4p3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29FAB224-3493-4273-A655-10BE44F5B5BE" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.4p4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "093F0DD2-9E88-4138-AFF5-69105E7F2C92" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.4p5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3590927-E242-411D-822A-33337D6B8A4B" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.4p6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20FCD55C-D4A8-4544-81AF-C920B3B48A2F" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "881ED983-01B5-4A02-B671-8744EC0E1904" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3897870-1724-4018-8F77-122548022535" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7012720C-D4BD-40C5-8521-6859BE46DDDC" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E8474ADA-F2A8-494D-BB6F-6EA4D4B865B1" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9FFC396E-2E5C-4576-94D3-96C619523CA6" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19F55042-5CA1-453E-A786-A8B346C02BC5" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A3C5930E-7792-4940-9EC3-CD5AE78D51B3" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "87004177-C6F2-4057-919D-20D91D01A8B2" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E01570E4-447A-4F60-BD5C-40D201A464F5" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "440B4315-C7B3-4930-BD4D-B55BD3EEEE9C" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "760050D5-5F8E-41CE-98DA-31E5BFB8A6C1" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "96E4FED4-A7F0-44C0-9405-1AB07D9B0079" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78977FE3-FF1E-47CA-9B97-3E6EC18894B7" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "11E24A99-575E-42EB-9463-29021A33C914" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CBB88D29-930C-4552-889D-4DBF23EC3760" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E13EE5C4-594E-4004-A8BC-AD4D3608FF35" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16009504-A8ED-43E9-A7F9-E8E1628449BF" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A4A86DA-E8CB-44B5-9E7D-A69A149FAF8E" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0F918DA-D4F3-4016-861E-78A8A00F9FEB" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD908ABD-5A18-436B-830B-7F252E22B3CF" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E8152815-3510-4FE7-A8B9-51EB857D7262" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p21:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C03D4FCB-A0CE-45EA-80FC-523F388E51A4" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p23:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86CBFD14-8B03-4F0D-8B0F-670629334D17" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p24:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "656E046B-C3F2-4DD5-B3C2-C60ACEBC808C" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p25:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "014A6026-C4B9-4E09-9170-059D1FD8D95A" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p26:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51BAB21E-C818-492A-A537-EFDF57E412EA" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p27:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92CACCD1-DF24-4226-A891-6FD7EBB0E57C" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p28:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "824DE9A3-5ABF-4E9F-985D-0633893CAECB" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p29:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A27E0EA-38B8-49F0-818B-BB4CAA7EF7B5" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p30:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8347419F-6B7F-4BA6-B03C-3A52E5F7148C" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p31:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23D73277-B636-4F50-88F0-A79278EB6AA1" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p32:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4701E3A4-FE51-4A48-8ABB-67DFE815BBFD" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p33:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A2E5F24-1242-4819-8787-4F2EB9E97C0E" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p35:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD55122C-2983-4193-BC46-6269A348EC5A" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p36:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D4199168-912C-4702-801C-A36394ED494B" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p37:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3D89067A-7F24-458A-AD6F-ADFB92C24F93" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p38:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "362FDB7C-EA5E-480D-96FB-2BCEF7F4E64A" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p39:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC3E2B20-E6B7-47DB-8A02-CAAF6C2B1597" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p40:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "98F3B4EA-053B-4A25-88F8-A788F88488A3" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p41:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "24B31D93-005E-498A-8935-EC31DC104B18" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p42:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "125D14D2-3443-46E6-AC58-967683604B2B" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p43:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2969C79-0B8F-4759-9978-7432BA388ADE" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p44:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "485E789D-B602-477E-BD10-0054AEE98D69" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p45:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83284150-1E06-45B0-BD75-7BE895EB99B5" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p46:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3298B973-D08A-44A6-AD60-0E18A9FF55AE" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p47:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06314717-CF64-4269-A049-F70396CA000A" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p48:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF909823-66E7-49AE-9385-DCDA7CD5EB51" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p49:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4FE8C8E-6051-4DB8-B03B-6EF211992545" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p50:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E1FF094E-49CA-41BB-A568-2BA49D770270" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p51:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE0D9B6F-3838-40ED-9998-89E66EEA79EC" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p52:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8076E3B3-57DA-425A-9CBD-426ADE3735F0" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p53:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E66A89E0-B31A-4469-859C-6C323399A706" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p54:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6813F72B-4D8B-4903-BCB7-5A0EDE288B93" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p55:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2F8F957C-632F-4E5D-82E3-B3DF6572C924" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p56:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0DC1DBF1-C2EE-4241-A50F-40E837B84C40" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p57:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7826192-660B-49AC-B1B8-BD799712DF55" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p58:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3443D451-1845-4440-AFB8-D6432585CBF8" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p59:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88C81B35-94C8-4881-B2FA-AF8214AAEBF8" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p60:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D3BDB8B-21E7-45EB-B39A-8822B64196ED" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p61:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "808929AC-EC57-49FF-9FCC-FE593743EE6F" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p62:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28C8CE4D-6C53-490E-8223-A6A4EEEA2CCB" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p63:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C49B2C1E-5653-4DA9-96A1-8E84A0AAB95E" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p64:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6DCD5198-26B4-4334-8077-916EA21F0760" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p65:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD533741-97B8-4726-A7C4-4B7D0723817E" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p66:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0336E989-FB7F-49CC-9FC9-F10B5C6716CC" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p67:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CD72509-2E02-4C18-8AB1-7FAB7016EB34" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p68:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EFD88BB1-C82A-4021-BEA3-40B23CA2A5CD" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p69:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79740F38-3210-4AF2-80C7-692DA5C5E315" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p70:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7A1FB0C1-3A68-41A3-9290-1CAA09042716" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p71:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4CA193DE-E94C-4229-8FBC-1E35884F310B" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5p73:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C76D8727-2324-4A2B-B73A-99E452FD07E4" } ], "operator": "OR" } ] } ]