← All CVEs

CVE-2009-1252

medium · 6.8

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

6.8
CVSS
21.3%
EPSS (exploit prob.)
97th
EPSS percentile
2009-05-19
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
ntpntp4.2.4p0
ntpntp4.2.4p1
ntpntp4.2.4p2
ntpntp4.2.4p3
ntpntp4.2.4p4
ntpntp4.2.4p5
ntpntp4.2.4p6
ntpntp4.2.5p0
ntpntp4.2.5p1
ntpntp4.2.5p2
ntpntp4.2.5p3
ntpntp4.2.5p4
ntpntp4.2.5p5
ntpntp4.2.5p6
ntpntp4.2.5p7
ntpntp4.2.5p8
ntpntp4.2.5p9
ntpntp4.2.5p10
ntpntp4.2.5p11
ntpntp4.2.5p12
ntpntp4.2.5p13
ntpntp4.2.5p14
ntpntp4.2.5p15
ntpntp4.2.5p16
ntpntp4.2.5p17
ntpntp4.2.5p18
ntpntp4.2.5p19
ntpntp4.2.5p20
ntpntp4.2.5p21
ntpntp4.2.5p23
ntpntp4.2.5p24
ntpntp4.2.5p25
ntpntp4.2.5p26
ntpntp4.2.5p27
ntpntp4.2.5p28
ntpntp4.2.5p29
ntpntp4.2.5p30
ntpntp4.2.5p31
ntpntp4.2.5p32
ntpntp4.2.5p33

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-1252