← All CVEs

CVE-2009-0159

medium · 6.8

Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.

6.8
CVSS
13.2%
EPSS (exploit prob.)
96th
EPSS percentile
2009-04-14
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
ntpntp<= 4.2.4p7
ntpntp4.0.72
ntpntp4.0.73
ntpntp4.0.90
ntpntp4.0.91
ntpntp4.0.92
ntpntp4.0.93
ntpntp4.0.94
ntpntp4.0.95
ntpntp4.0.96
ntpntp4.0.97
ntpntp4.0.98
ntpntp4.0.99
ntpntp4.1.0
ntpntp4.1.2
ntpntp4.2.0
ntpntp4.2.2
ntpntp4.2.2p1
ntpntp4.2.2p2
ntpntp4.2.2p3
ntpntp4.2.2p4
ntpntp4.2.4
ntpntp4.2.4p0
ntpntp4.2.4p1
ntpntp4.2.4p2
ntpntp4.2.4p3
ntpntp4.2.4p4
ntpntp4.2.4p5
ntpntp4.2.4p6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-0159