← Back

CVE-2017-6451

nvd nist
Published: Mar 27, 2017Modified: May 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which trigger an out-of-bounds memory write.

Affected (95)

Products: Ntp: Ntp
1 product
Ntp
Configuration A
95 vulnerable
Vulnerable SoftwareAffected Versions
Ntp
Version 4.2.8 p9
Version 4.3.0
Version 4.3.10
Version 4.3.11
Version 4.3.12
Version 4.3.13
Version 4.3.14
Version 4.3.15
Version 4.3.16
Version 4.3.17
Version 4.3.18
Version 4.3.19
Version 4.3.1
Version 4.3.20
Version 4.3.21
Version 4.3.22
Version 4.3.23
Version 4.3.24
Version 4.3.25
Version 4.3.26
Version 4.3.27
Version 4.3.28
Version 4.3.29
Version 4.3.2
Version 4.3.30
Version 4.3.31
Version 4.3.32
Version 4.3.33
Version 4.3.34
Version 4.3.35
Version 4.3.36
Version 4.3.37
Version 4.3.38
Version 4.3.39
Version 4.3.3
Version 4.3.40
Version 4.3.41
Version 4.3.42
Version 4.3.43
Version 4.3.44
Version 4.3.45
Version 4.3.46
Version 4.3.47
Version 4.3.48
Version 4.3.49
Version 4.3.4
Version 4.3.50
Version 4.3.51
Version 4.3.52
Version 4.3.53
Version 4.3.54
Version 4.3.55
Version 4.3.56
Version 4.3.57
Version 4.3.58
Version 4.3.59
Version 4.3.5
Version 4.3.60
Version 4.3.61
Version 4.3.62
Version 4.3.63
Version 4.3.64
Version 4.3.65
Version 4.3.66
Version 4.3.67
Version 4.3.68
Version 4.3.69
Version 4.3.6
Version 4.3.70
Version 4.3.71
Version 4.3.72
Version 4.3.73
Version 4.3.74
Version 4.3.75
Version 4.3.76
Version 4.3.77
Version 4.3.78
Version 4.3.79
Version 4.3.7
Version 4.3.80
Version 4.3.81
Version 4.3.82
Version 4.3.83
Version 4.3.84
Version 4.3.85
Version 4.3.86
Version 4.3.87
Version 4.3.88
Version 4.3.89
Version 4.3.8
Version 4.3.90
Version 4.3.91
Version 4.3.92
Version 4.3.93
Version 4.3.9

References (14)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.