CVE-2009-0159

Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
ntpntp
𝑥
≤ 4.2.4p7
ntpntp
4.0.72
ntpntp
4.0.73
ntpntp
4.0.90
ntpntp
4.0.91
ntpntp
4.0.92
ntpntp
4.0.93
ntpntp
4.0.94
ntpntp
4.0.95
ntpntp
4.0.96
ntpntp
4.0.97
ntpntp
4.0.98
ntpntp
4.0.99
ntpntp
4.1.0
ntpntp
4.1.2
ntpntp
4.2.0
ntpntp
4.2.2
ntpntp
4.2.2p1:p1
ntpntp
4.2.2p2:p2
ntpntp
4.2.2p3:p3
ntpntp
4.2.2p4:p4
ntpntp
4.2.4
ntpntp
4.2.4p0:p0
ntpntp
4.2.4p1:p1
ntpntp
4.2.4p2:p2
ntpntp
4.2.4p3:p3
ntpntp
4.2.4p4:p4
ntpntp
4.2.4p5:p5
ntpntp
4.2.4p6:p6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ntp
bullseye
1:4.2.8p15+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ntp
jaunty
Fixed 1:4.2.4p4+dfsg-7ubuntu5.1
released
intrepid
Fixed 1:4.2.4p4+dfsg-6ubuntu2.3
released
hardy
Fixed 1:4.2.4p4+dfsg-3ubuntu2.2
released
gutsy
ignored
dapper
Fixed 1:4.2.0a+stable-8.1ubuntu6.2
released
References