CVE-2017-6458

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.

References

http://www.securitytracker.com/id/1038123

http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secu

http://support.ntp.org/bin/view/Main/NtpBug3379

http://www.securityfocus.com/bid/97051

https://support.apple.com/HT208144

https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us

https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdf

Details

Source: MITRE

Published: 2017-03-27

Updated: 2021-07-12

Type: CWE-119

Risk Information

CVSS v2

Base Score: 6.5

Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8

Severity: MEDIUM

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH

Tenable Plugins

View all (18 total)

IDNameProductFamilySeverity
700511macOS < 10.13 Multiple VulnerabilitiesNessus Network MonitorOperating System Detection
critical
121678Photon OS 1.0: Ntp PHSA-2017-0010NessusPhotonOS Local Security Checks
high
111859Photon OS 1.0: Binutils / Libarchive / Ntp PHSA-2017-0010 (deprecated)NessusPhotonOS Local Security Checks
critical
105471F5 Networks BIG-IP : NTP vulnerability (K99254031)NessusF5 Networks Local Security Checks
high
103598macOS < 10.13 Multiple VulnerabilitiesNessusMacOS X Local Security Checks
critical
102131AIX NTP v4 Advisory : ntp_advisory9.asc (IV96311) (IV96312)NessusAIX Local Security Checks
high
102130AIX NTP v3 Advisory : ntp_advisory9.asc (IV96305) (IV96306) (IV96307) (IV96308) (IV96309) (IV96310)NessusAIX Local Security Checks
high
101588Fedora 26 : ntp (2017-20d54b2782)NessusFedora Local Security Checks
high
101263Ubuntu 14.04 LTS / 16.04 LTS / 16.10 / 17.04 : ntp vulnerabilities (USN-3349-1)NessusUbuntu Local Security Checks
high
99700openSUSE Security Update : ntp (openSUSE-2017-511)NessusSuSE Local Security Checks
high
99597Slackware 13.0 / 13.1 / 13.37 / 14.0 / 14.1 / 14.2 / current : ntp (SSA:2017-112-02)NessusSlackware Local Security Checks
high
99529Amazon Linux AMI : ntp (ALAS-2017-816)NessusAmazon Linux Local Security Checks
high
99469SUSE SLES11 Security Update : ntp (SUSE-SU-2017:1052-1)NessusSuSE Local Security Checks
high
99468SUSE SLED12 / SLES12 Security Update : ntp (SUSE-SU-2017:1048-1)NessusSuSE Local Security Checks
high
99467SUSE SLES12 Security Update : ntp (SUSE-SU-2017:1047-1)NessusSuSE Local Security Checks
high
99445Fedora 24 : ntp (2017-72323a442f)NessusFedora Local Security Checks
high
99053Fedora 25 : ntp (2017-5ebac1c112)NessusFedora Local Security Checks
high
97988Network Time Protocol Daemon (ntpd) 4.x < 4.2.8p10 Multiple VulnerabilitiesNessusMisc.
high