CVE-2014-9750

MEDIUM
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field.

References

http://bugs.ntp.org/show_bug.cgi?id=2671

http://rhn.redhat.com/errata/RHSA-2015-1459.html

http://support.ntp.org/bin/view/Main/SecurityNotice#December_2014_NTP_Security_Vulne

http://www.debian.org/security/2015/dsa-3388

http://www.kb.cert.org/vuls/id/852879

http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html

http://www.securityfocus.com/bid/72583

https://bugzilla.redhat.com/show_bug.cgi?id=1184573

https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03886en_us

Details

Source: MITRE

Published: 2015-10-06

Updated: 2020-06-18

Type: CWE-20

Risk Information

CVSS v2

Base Score: 5.8

Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Impact Score: 4.9

Exploitability Score: 8.6

Severity: MEDIUM

Tenable Plugins

View all (16 total)

IDNameProductFamilySeverity
125009EulerOS Virtualization 3.0.1.0 : ntp (EulerOS-SA-2019-1556)NessusHuawei Local Security Checks
critical
95850Scientific Linux Security Update : ntp on SL7.x x86_64 (20161103)NessusScientific Linux Local Security Checks
high
91539Scientific Linux Security Update : ntp on SL6.x i386/x86_64 (20160510)NessusScientific Linux Local Security Checks
high
87564Scientific Linux Security Update : ntp on SL7.x x86_64 (20151119)NessusScientific Linux Local Security Checks
high
87143CentOS 7 : ntp (CESA-2015:2231)NessusCentOS Local Security Checks
high
87030Oracle Linux 7 : ntp (ELSA-2015-2231)NessusOracle Linux Local Security Checks
high
86975RHEL 7 : ntp (RHSA-2015:2231)NessusRed Hat Local Security Checks
high
86773F5 Networks BIG-IP : NTP vulnerabilities (K17530)NessusF5 Networks Local Security Checks
high
86682Debian DSA-3388-1 : ntp - security updateNessusDebian Local Security Checks
critical
86664Slackware 13.0 / 13.1 / 13.37 / 14.0 / 14.1 / current : ntp (SSA:2015-302-03)NessusSlackware Local Security Checks
critical
85949F5 Networks BIG-IP : NTP vulnerability (SOL16392)NessusF5 Networks Local Security Checks
medium
85111Oracle Linux 6 : ntp (ELSA-2015-1459)NessusOracle Linux Local Security Checks
high
85025CentOS 6 : ntp (CESA-2015:1459)NessusCentOS Local Security Checks
high
84951RHEL 6 : ntp (RHSA-2015:1459)NessusRed Hat Local Security Checks
high
81981Network Time Protocol Daemon (ntpd) 4.x < 4.2.8p1 Multiple VulnerabilitiesNessusMisc.
critical
81189Debian DSA-3154-1 : ntp - security updateNessusDebian Local Security Checks
medium