← All CVEs

CVE-2009-3563

medium · 6.4

ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.

6.4
CVSS
32.1%
EPSS (exploit prob.)
98th
EPSS percentile
2009-12-09
Published

AV:N/AC:L/Au:N/C:N/I:P/A:P

Affected products

VendorProductAffected versions
ntpntp<= 4.2.2p4
ntpntp4.0.72
ntpntp4.0.73
ntpntp4.0.90
ntpntp4.0.91
ntpntp4.0.92
ntpntp4.0.93
ntpntp4.0.94
ntpntp4.0.95
ntpntp4.0.96
ntpntp4.0.97
ntpntp4.0.98
ntpntp4.0.99
ntpntp4.1.0
ntpntp4.1.2
ntpntp4.2.0
ntpntp4.2.2
ntpntp4.2.2p1
ntpntp4.2.2p2
ntpntp4.2.2p3
ntpntp4.2.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-3563