CVE-2009-0021
published 2009-01-07CVE-2009-0021: NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote…
PriorityP427medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
3.10%
86.4th percentile
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.4p4+dfsg-8 (bullseye) | ntp 1:4.2.4p4+dfsg-8 (bullseye) |
| ntp | ntp | <= 4.2.4p4 | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.4p4+dfsg-8 | 1:4.2.4p4+dfsg-8 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-09:03.ntpd: ntpd cryptographic signature bypass
bsd_advisories·2009-01-13·CVSS 5.0
CVE-2009-0021 [MEDIUM] FreeBSD-SA-09:03.ntpd: ntpd cryptographic signature bypass
FreeBSD-SA-09:03.ntpd Security Advisory
The FreeBSD Project
Topic: ntpd cryptographic signature bypass
Category: contrib
Module: ntpd
Announced: 2009-01-13
Credits: Google Security Team
Affects: All FreeBSD releases
Corrected: 2009-01-13 21:19:27 UTC (RELENG_7, 7.1-STABLE)
2009-01-13 21:19:27 UTC (RELENG_7_1, 7.1-RELEASE-p2)
2009-01-13 21:19:27 UTC (RELENG_7_0, 7.0-RELEASE-p9)
2009-01-13 21:19:27 UTC (RELENG_6, 6.4-STABLE)
2009-01-13 21:19:27 UTC (RELENG_6_4, 6.4-RELEASE-p3)
2009-01-13 21:19:27 UTC (RELENG_6_3, 6.3-RELEASE-p9)
CVE Name: CVE-2009-0021
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The ntpd daemon is an implementation of the Network Tim
Ubuntu
NTP vulnerability
vendor_ubuntu·2009-01-08
CVE-2009-0021 NTP vulnerability
Title: NTP vulnerability
Summary: NTP vulnerability
It was discovered that NTP did not properly perform signature verification.
A remote attacker could exploit this to bypass certificate validation via
a malformed SSL/TLS signature.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
ntp incorrectly checks for malformed signatures
vendor_redhat·2009-01-07·CVSS 5.8
CVE-2009-0021 [MEDIUM] ntp incorrectly checks for malformed signatures
ntp incorrectly checks for malformed signatures
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
Debian
CVE-2009-0021: ntp - NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the ...
vendor_debian·2009·CVSS 5.8
CVE-2009-0021 [MEDIUM] CVE-2009-0021: ntp - NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the ...
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
Scope: local
bullseye: resolved (fixed in 1:4.2.4p4+dfsg-8)
GHSA
GHSA-4q4m-qx69-vcgq: NTP 4
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0021 [MEDIUM] CWE-287 GHSA-4q4m-qx69-vcgq: NTP 4
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
OSV
CVE-2009-0021: NTP 4
osv·2009-01-07·CVSS 5.8
CVE-2009-0021 [MEDIUM] CVE-2009-0021: NTP 4
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlhttp://secunia.com/advisories/33406http://secunia.com/advisories/33558http://secunia.com/advisories/33648http://secunia.com/advisories/34642http://secunia.com/advisories/35074http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.531177http://support.apple.com/kb/HT3549http://www.ocert.org/advisories/ocert-2008-016.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0046.htmlhttp://www.securityfocus.com/archive/1/499827/100/0/threadedhttp://www.securitytracker.com/id?1021533http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/0042http://www.vupen.com/english/advisories/2009/1297https://lists.ntp.org/pipermail/announce/2009-January/000055.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10035http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlhttp://secunia.com/advisories/33406http://secunia.com/advisories/33558http://secunia.com/advisories/33648http://secunia.com/advisories/34642http://secunia.com/advisories/35074http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.531177http://support.apple.com/kb/HT3549http://www.ocert.org/advisories/ocert-2008-016.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0046.htmlhttp://www.securityfocus.com/archive/1/499827/100/0/threadedhttp://www.securitytracker.com/id?1021533http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/0042http://www.vupen.com/english/advisories/2009/1297https://lists.ntp.org/pipermail/announce/2009-January/000055.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10035
2009-01-07
Published