CVE-2009-3563
Published Dec 9, 2009
Last updated 8 months ago
Overview
- Description
- ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "73B1FD64-D156-45BC-9713-77E163DF731C", "versionEndIncluding": "4.2.2p4" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.72:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "25AB2D70-2807-4970-ACD3-9B4751A1F9D6" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.73:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06C78C19-5A09-4883-8144-AE861A244FEA" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.90:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "437C8BA8-F437-4166-838D-EDC64E7A67DC" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.91:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "104AEC97-3C2A-48D2-BA63-08502F88F8D2" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.92:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "87D67E30-E303-4F79-9929-4A5B587FCDB7" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.93:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9BD95B5-322C-4CDC-A2DB-A06D4DA3B104" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.94:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0BD63969-D18D-41AF-9814-DA1A207BDE80" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.95:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7EAD8958-173A-4FCC-9420-A148BA5F73E2" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.96:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B271F6AD-D829-4671-8FA7-7D921364B426" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.97:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C25E03A8-46B5-4AC7-8506-4C255D7CC400" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.98:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C76CD53-CC9F-491A-952F-9A82D6E20058" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.0.99:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E749D64E-5C47-4A34-9F3C-1D34F8348058" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE0C9CBB-D52F-4F7C-B343-E685A3996BC6" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB90A3FB-B107-46CF-A846-48EE0EDF637A" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "088BFFA4-1AAB-4699-9793-F731A81B296A" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3475779-383A-4128-9145-474EC08030FE" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.2p1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "782BAA3D-A639-4B25-83F0-741074C88D7F" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.2p2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF367FA4-2C7F-4040-89DE-8A97A069A802" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.2p3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "01D11498-3FC4-4890-9B10-BBA74A01C9E7" }, { "criteria": "cpe:2.3:a:ntp:ntp:4.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35C2B888-66D6-45D3-97E3-C711B1C6971A" } ], "operator": "OR" } ] } ]