CVE Database
/

CVE-2014-9295

Back to search

CVE-2014-9295

Published: Dec 20, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authentication feature is used, (2) the ctl_putdata function, and (3) the configure function.

VendorProductVersions

n/a

n/a

affected
n/a

References

71761
vdb-entry
x_refsource_BID
HPSBGN03277
vendor-advisory
x_refsource_HP
VU#852879
third-party-advisory
x_refsource_CERT-VN
HPSBUX03240
vendor-advisory
x_refsource_HP
RHSA-2014:2025
vendor-advisory
x_refsource_REDHAT
62209
third-party-advisory
x_refsource_SECUNIA
RHSA-2015:0104
vendor-advisory
x_refsource_REDHAT
HPSBOV03505
vendor-advisory
x_refsource_HP
SSRT101872
vendor-advisory
x_refsource_HP
openSUSE-SU-2014:1670
vendor-advisory
x_refsource_SUSE
HPSBPV03266
vendor-advisory
x_refsource_HP
MDVSA-2015:003
vendor-advisory
x_refsource_MANDRIVA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now