Back to search
CVE-2014-9751
Published: Oct 4, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
VU#852879
third-party-advisory
x_refsource_CERT-VN
http://bugs.ntp.org/show_bug.cgi?id=2672
x_refsource_CONFIRM
DSA-3388
vendor-advisory
x_refsource_DEBIAN
72584
vdb-entry
x_refsource_BID
RHSA-2015:1459
vendor-advisory
x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=1184572
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now