Back to search
CVE-2009-1252
Published: May 19, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-777-1
vendor-advisory
x_refsource_UBUNTU
35137
third-party-advisory
x_refsource_SECUNIA
35166
third-party-advisory
x_refsource_SECUNIA
37470
third-party-advisory
x_refsource_SECUNIA
35388
third-party-advisory
x_refsource_SECUNIA
35243
third-party-advisory
x_refsource_SECUNIA
37471
third-party-advisory
x_refsource_SECUNIA
DSA-1801
vendor-advisory
x_refsource_DEBIAN
FEDORA-2009-5275
vendor-advisory
x_refsource_FEDORA
35308
third-party-advisory
x_refsource_SECUNIA
35253
third-party-advisory
x_refsource_SECUNIA
https://support.ntp.org/bugs/show_bug.cgi?id=1151
x_refsource_CONFIRM
MDVSA-2009:117
vendor-advisory
x_refsource_MANDRIVA
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
x_refsource_CONFIRM
http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0092
x_refsource_CONFIRM
1022243
vdb-entry
x_refsource_SECTRACK
35138
third-party-advisory
x_refsource_SECUNIA
SSA:2009-154-01
vendor-advisory
x_refsource_SLACKWARE
FEDORA-2009-5273
vendor-advisory
x_refsource_FEDORA
SUSE-SR:2009:011
vendor-advisory
x_refsource_SUSE
FEDORA-2009-5674
vendor-advisory
x_refsource_FEDORA
35630
third-party-advisory
x_refsource_SECUNIA
https://launchpad.net/bugs/cve/2009-1252
x_refsource_MISC
oval:org.mitre.oval:def:11231
vdb-entry
signature
x_refsource_OVAL
https://bugzilla.redhat.com/show_bug.cgi?id=499694
x_refsource_CONFIRM
35017
vdb-entry
x_refsource_BID
RHSA-2009:1040
vendor-advisory
x_refsource_REDHAT
FreeBSD-SA-09:11
vendor-advisory
x_refsource_FREEBSD
35416
third-party-advisory
x_refsource_SECUNIA
VU#853097
third-party-advisory
x_refsource_CERT-VN
35336
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:1039
vendor-advisory
x_refsource_REDHAT
ADV-2009-1361
vdb-entry
x_refsource_VUPEN
oval:org.mitre.oval:def:6307
vdb-entry
signature
x_refsource_OVAL
35169
third-party-advisory
x_refsource_SECUNIA
GLSA-200905-08
vendor-advisory
x_refsource_GENTOO
ADV-2009-3316
vdb-entry
x_refsource_VUPEN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now