CVE-2009-0021

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
ntpntp
𝑥
≤ 4.2.4p4
ntpntp
4.2.0
ntpntp
4.2.2
ntpntp
4.2.4p1:p1
ntpntp
4.2.4p2:p2
ntpntp
4.2.4p3:p3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ntp
bullseye
1:4.2.8p15+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ntp
intrepid
Fixed 1:4.2.4p4+dfsg-6ubuntu2.2
released
hardy
Fixed 1:4.2.4p4+dfsg-3ubuntu2.1
released
gutsy
Fixed 1:4.2.4p0+dfsg-1ubuntu2.1
released
dapper
Fixed 1:4.2.0a+stable-8.1ubuntu6.1
released
References