CVE-2009-0159

EUVD-2009-0168
Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
Affected Products (NVD)
VendorProductVersion
ntpntp
𝑥
≤ 4.2.4p7
ntpntp
4.0.72
ntpntp
4.0.73
ntpntp
4.0.90
ntpntp
4.0.91
ntpntp
4.0.92
ntpntp
4.0.93
ntpntp
4.0.94
ntpntp
4.0.95
ntpntp
4.0.96
ntpntp
4.0.97
ntpntp
4.0.98
ntpntp
4.0.99
ntpntp
4.1.0
ntpntp
4.1.2
ntpntp
4.2.0
ntpntp
4.2.2
ntpntp
4.2.2p1:p1
ntpntp
4.2.2p2:p2
ntpntp
4.2.2p3:p3
ntpntp
4.2.2p4:p4
ntpntp
4.2.4
ntpntp
4.2.4p0:p0
ntpntp
4.2.4p1:p1
ntpntp
4.2.4p2:p2
ntpntp
4.2.4p3:p3
ntpntp
4.2.4p4:p4
ntpntp
4.2.4p5:p5
ntpntp
4.2.4p6:p6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ntp
bullseye
1:4.2.8p15+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ntp
dapper
Fixed 1:4.2.0a+stable-8.1ubuntu6.2
released
gutsy
ignored
hardy
Fixed 1:4.2.4p4+dfsg-3ubuntu2.2
released
intrepid
Fixed 1:4.2.4p4+dfsg-6ubuntu2.3
released
jaunty
Fixed 1:4.2.4p4+dfsg-7ubuntu5.1
released
References