CVE Database
/

CVE-2009-1252

Back to search

CVE-2009-1252

Published: May 19, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-777-1
vendor-advisory
x_refsource_UBUNTU
35137
third-party-advisory
x_refsource_SECUNIA
35166
third-party-advisory
x_refsource_SECUNIA
37470
third-party-advisory
x_refsource_SECUNIA
35388
third-party-advisory
x_refsource_SECUNIA
35243
third-party-advisory
x_refsource_SECUNIA
37471
third-party-advisory
x_refsource_SECUNIA
DSA-1801
vendor-advisory
x_refsource_DEBIAN
FEDORA-2009-5275
vendor-advisory
x_refsource_FEDORA
35308
third-party-advisory
x_refsource_SECUNIA
35253
third-party-advisory
x_refsource_SECUNIA
MDVSA-2009:117
vendor-advisory
x_refsource_MANDRIVA
1022243
vdb-entry
x_refsource_SECTRACK
35138
third-party-advisory
x_refsource_SECUNIA
SSA:2009-154-01
vendor-advisory
x_refsource_SLACKWARE
FEDORA-2009-5273
vendor-advisory
x_refsource_FEDORA
SUSE-SR:2009:011
vendor-advisory
x_refsource_SUSE
FEDORA-2009-5674
vendor-advisory
x_refsource_FEDORA
35630
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:11231
vdb-entry
signature
x_refsource_OVAL
35017
vdb-entry
x_refsource_BID
RHSA-2009:1040
vendor-advisory
x_refsource_REDHAT
FreeBSD-SA-09:11
vendor-advisory
x_refsource_FREEBSD
35416
third-party-advisory
x_refsource_SECUNIA
VU#853097
third-party-advisory
x_refsource_CERT-VN
35336
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:1039
vendor-advisory
x_refsource_REDHAT
ADV-2009-1361
vdb-entry
x_refsource_VUPEN
oval:org.mitre.oval:def:6307
vdb-entry
signature
x_refsource_OVAL
35169
third-party-advisory
x_refsource_SECUNIA
GLSA-200905-08
vendor-advisory
x_refsource_GENTOO
ADV-2009-3316
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now