CVE-2009-1252

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
ntpntp
4.2.4p0:p0
ntpntp
4.2.4p1:p1
ntpntp
4.2.4p2:p2
ntpntp
4.2.4p3:p3
ntpntp
4.2.4p4:p4
ntpntp
4.2.4p5:p5
ntpntp
4.2.4p6:p6
ntpntp
4.2.5p0:p0
ntpntp
4.2.5p1:p1
ntpntp
4.2.5p2:p2
ntpntp
4.2.5p3:p3
ntpntp
4.2.5p4:p4
ntpntp
4.2.5p5:p5
ntpntp
4.2.5p6:p6
ntpntp
4.2.5p7:p7
ntpntp
4.2.5p8:p8
ntpntp
4.2.5p9:p9
ntpntp
4.2.5p10:p10
ntpntp
4.2.5p11:p11
ntpntp
4.2.5p12:p12
ntpntp
4.2.5p13:p13
ntpntp
4.2.5p14:p14
ntpntp
4.2.5p15:p15
ntpntp
4.2.5p16:p16
ntpntp
4.2.5p17:p17
ntpntp
4.2.5p18:p18
ntpntp
4.2.5p19:p19
ntpntp
4.2.5p20:p20
ntpntp
4.2.5p21:p21
ntpntp
4.2.5p23:p23
ntpntp
4.2.5p24:p24
ntpntp
4.2.5p25:p25
ntpntp
4.2.5p26:p26
ntpntp
4.2.5p27:p27
ntpntp
4.2.5p28:p28
ntpntp
4.2.5p29:p29
ntpntp
4.2.5p30:p30
ntpntp
4.2.5p31:p31
ntpntp
4.2.5p32:p32
ntpntp
4.2.5p33:p33
ntpntp
4.2.5p35:p35
ntpntp
4.2.5p36:p36
ntpntp
4.2.5p37:p37
ntpntp
4.2.5p38:p38
ntpntp
4.2.5p39:p39
ntpntp
4.2.5p40:p40
ntpntp
4.2.5p41:p41
ntpntp
4.2.5p42:p42
ntpntp
4.2.5p43:p43
ntpntp
4.2.5p44:p44
ntpntp
4.2.5p45:p45
ntpntp
4.2.5p46:p46
ntpntp
4.2.5p47:p47
ntpntp
4.2.5p48:p48
ntpntp
4.2.5p49:p49
ntpntp
4.2.5p50:p50
ntpntp
4.2.5p51:p51
ntpntp
4.2.5p52:p52
ntpntp
4.2.5p53:p53
ntpntp
4.2.5p54:p54
ntpntp
4.2.5p55:p55
ntpntp
4.2.5p56:p56
ntpntp
4.2.5p57:p57
ntpntp
4.2.5p58:p58
ntpntp
4.2.5p59:p59
ntpntp
4.2.5p60:p60
ntpntp
4.2.5p61:p61
ntpntp
4.2.5p62:p62
ntpntp
4.2.5p63:p63
ntpntp
4.2.5p64:p64
ntpntp
4.2.5p65:p65
ntpntp
4.2.5p66:p66
ntpntp
4.2.5p67:p67
ntpntp
4.2.5p68:p68
ntpntp
4.2.5p69:p69
ntpntp
4.2.5p70:p70
ntpntp
4.2.5p71:p71
ntpntp
4.2.5p73:p73
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ntp
bullseye
1:4.2.8p15+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ntp
jaunty
Fixed 1:4.2.4p4+dfsg-7ubuntu5.1
released
intrepid
Fixed 1:4.2.4p4+dfsg-6ubuntu2.3
released
hardy
Fixed 1:4.2.4p4+dfsg-3ubuntu2.2
released
dapper
Fixed 1:4.2.0a+stable-8.1ubuntu6.2
released
References