← Back

CVE-2009-1252

nvd nist
Published: May 19, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

Affected (78)

Products: Ntp: Ntp
1 product
Ntp
Configuration A
78 vulnerable
Vulnerable SoftwareAffected Versions
Ntp
Version 4.2.4p0
Version 4.2.4p1
Version 4.2.4p2
Version 4.2.4p3
Version 4.2.4p4
Version 4.2.4p5
Version 4.2.4p6
Version 4.2.5p0
Version 4.2.5p10
Version 4.2.5p11
Version 4.2.5p12
Version 4.2.5p13
Version 4.2.5p14
Version 4.2.5p15
Version 4.2.5p16
Version 4.2.5p17
Version 4.2.5p18
Version 4.2.5p19
Version 4.2.5p1
Version 4.2.5p20
Version 4.2.5p21
Version 4.2.5p23
Version 4.2.5p24
Version 4.2.5p25
Version 4.2.5p26
Version 4.2.5p27
Version 4.2.5p28
Version 4.2.5p29
Version 4.2.5p2
Version 4.2.5p30
Version 4.2.5p31
Version 4.2.5p32
Version 4.2.5p33
Version 4.2.5p35
Version 4.2.5p36
Version 4.2.5p37
Version 4.2.5p38
Version 4.2.5p39
Version 4.2.5p3
Version 4.2.5p40
Version 4.2.5p41
Version 4.2.5p42
Version 4.2.5p43
Version 4.2.5p44
Version 4.2.5p45
Version 4.2.5p46
Version 4.2.5p47
Version 4.2.5p48
Version 4.2.5p49
Version 4.2.5p4
Version 4.2.5p50
Version 4.2.5p51
Version 4.2.5p52
Version 4.2.5p53
Version 4.2.5p54
Version 4.2.5p55
Version 4.2.5p56
Version 4.2.5p57
Version 4.2.5p58
Version 4.2.5p59
Version 4.2.5p5
Version 4.2.5p60
Version 4.2.5p61
Version 4.2.5p62
Version 4.2.5p63
Version 4.2.5p64
Version 4.2.5p65
Version 4.2.5p66
Version 4.2.5p67
Version 4.2.5p68
Version 4.2.5p69
Version 4.2.5p6
Version 4.2.5p70
Version 4.2.5p71
Version 4.2.5p73
Version 4.2.5p7
Version 4.2.5p8
Version 4.2.5p9

References (78)

ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-006.txt.asc (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-006.txt.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.