CVE-2014-9750
published 2015-10-06CVE-2014-9750: ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process…
PriorityP430medium5.8CVSS 2.0
AVNACMAuNCPINAP
EPSS
6.13%
92.7th percentile
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ntp | < ntp 1:4.2.8p4+dfsg-1 (bullseye) | ntp 1:4.2.8p4+dfsg-1 (bullseye) |
| debian | ntp | < ntp 1:4.2.6.p5+dfsg-5 (bullseye) | ntp 1:4.2.6.p5+dfsg-5 (bullseye) |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p4+dfsg-1 | 1:4.2.8p4+dfsg-1 |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-5 | 1:4.2.6.p5+dfsg-5 |
| ntp | ntp | >= 4.2.0 < 4.2.8 | 4.2.8 |
| ntp | ntp | >= 4.3.0 < 4.3.77 | 4.3.77 |
| oracle | linux | — | — |
| oracle | linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9qvp-w68q-7r55: The crypto_xmit function in ntpd in NTP 4
ghsa_unreviewed·2022-05-13·CVSS 5.8
CVE-2015-7692 [MEDIUM] CWE-20 GHSA-9qvp-w68q-7r55: The crypto_xmit function in ntpd in NTP 4
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
GHSA
GHSA-fqg8-938p-4rx7: The crypto_xmit function in ntpd in NTP 4
ghsa_unreviewed·2022-05-13·CVSS 5.8
CVE-2015-7702 [MEDIUM] CWE-20 GHSA-fqg8-938p-4rx7: The crypto_xmit function in ntpd in NTP 4
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
GHSA
GHSA-2cm3-5rf2-6c3w: The crypto_xmit function in ntpd in NTP 4
ghsa_unreviewed·2022-05-13·CVSS 5.8
CVE-2015-7691 [MEDIUM] CWE-20 GHSA-2cm3-5rf2-6c3w: The crypto_xmit function in ntpd in NTP 4
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
GHSA
GHSA-2cf6-qqmm-m55v: ntp_crypto
ghsa_unreviewed·2022-05-13
CVE-2014-9750 [MEDIUM] CWE-20 GHSA-2cf6-qqmm-m55v: ntp_crypto
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field.
OSV
CVE-2015-7692: The crypto_xmit function in ntpd in NTP 4
osv·2017-08-07·CVSS 5.8
CVE-2015-7692 [MEDIUM] CVE-2015-7692: The crypto_xmit function in ntpd in NTP 4
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
OSV
CVE-2015-7702: The crypto_xmit function in ntpd in NTP 4
osv·2017-08-07·CVSS 5.8
CVE-2015-7702 [MEDIUM] CVE-2015-7702: The crypto_xmit function in ntpd in NTP 4
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
OSV
CVE-2015-7691: The crypto_xmit function in ntpd in NTP 4
osv·2017-08-07·CVSS 5.8
CVE-2015-7691 [MEDIUM] CVE-2015-7691: The crypto_xmit function in ntpd in NTP 4
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
OSV
CVE-2014-9750: ntp_crypto
osv·2015-10-06·CVSS 5.8
CVE-2014-9750 [MEDIUM] CVE-2014-9750: ntp_crypto
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field.
BSD
FreeBSD-SA-15:25.ntp: Multiple vulnerabilities of ntp [REVISED]
bsd_advisories·2015-10-26·CVSS 7.5
CVE-2014-9750 [HIGH] FreeBSD-SA-15:25.ntp: Multiple vulnerabilities of ntp [REVISED]
FreeBSD-SA-15:25.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp [REVISED]
Category: contrib
Module: ntp
Announced: 2015-10-26, revised on 2015-11-04
Credits: Network Time Foundation
Affects: All supported versions of FreeBSD.
Corrected: 2015-10-26 11:35:40 UTC (stable/10, 10.2-STABLE)
2015-11-04 11:27:13 UTC (releng/10.2, 10.2-RELEASE-p7)
2015-11-04 11:27:21 UTC (releng/10.1, 10.1-RELEASE-p24)
2015-11-02 10:39:26 UTC (stable/9, 9.3-STABLE)
2015-11-04 11:27:30 UTC (releng/9.3, 9.3-RELEASE-p30)
CVE Name: CVE-2015-7701, CVE-2015-7702, CVE-2015-7703, CVE-2015-7704,
CVE-2015-7848, CVE-2015-7849, CVE-2015-7850, CVE-2015-7851,
CVE-2015-7852, CVE-2015-7853, CVE-2015-7854, CVE-2015-7855,
CVE-2015-7871
For general information regarding FreeBSD Security Advisories
Red Hat
ntp: incomplete checks in ntp_crypto.c
vendor_redhat·2015-10-21·CVSS 5.8
CVE-2015-7702 [MEDIUM] ntp: incomplete checks in ntp_crypto.c
ntp: incomplete checks in ntp_crypto.c
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
It was found that the fix for CVE-2014-9750 was incomplete: three issues were found in the value length checks in NTP's ntp_crypto.c, where a packet with particular autokey operations that contained malicious data was not always being completely validated. A remote attacker could use a specially crafted NTP packet to crash ntpd.
Mitigation: Disable NTP autokey authentication by removing, or commenting out, all configuration directives beginning with the 'crypto' keyword in your ntp.conf file.
Package: ntp (Red Hat Enterprise Li
Red Hat
ntp: incomplete checks in ntp_crypto.c
vendor_redhat·2015-10-21·CVSS 5.8
CVE-2015-7691 [MEDIUM] ntp: incomplete checks in ntp_crypto.c
ntp: incomplete checks in ntp_crypto.c
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
It was found that the fix for CVE-2014-9750 was incomplete: three issues were found in the value length checks in NTP's ntp_crypto.c, where a packet with particular autokey operations that contained malicious data was not always being completely validated. A remote attacker could use a specially crafted NTP packet to crash ntpd.
Mitigation: Disable NTP autokey authentication by removing, or commenting out, all configuration directives beginning with the 'crypto' keywor
Red Hat
ntp: incomplete checks in ntp_crypto.c
vendor_redhat·2015-10-21·CVSS 5.8
CVE-2015-7692 [MEDIUM] ntp: incomplete checks in ntp_crypto.c
ntp: incomplete checks in ntp_crypto.c
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
It was found that the fix for CVE-2014-9750 was incomplete: three issues were found in the value length checks in NTP's ntp_crypto.c, where a packet with particular autokey operations that contained malicious data was not always being completely validated. A remote attacker could use a specially crafted NTP packet to crash ntpd.
Mitigation: Disable NTP autokey authentication by removing, or commenting out, all configuration directives beginning with the 'crypto' keyword in your ntp.conf file.
Package: ntp (Red Hat Enterprise Li
Red Hat
ntp: vallen in extension fields are not validated
vendor_redhat·2015-02-04·CVSS 5.8
CVE-2014-9750 [MEDIUM] ntp: vallen in extension fields are not validated
ntp: vallen in extension fields are not validated
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field.
A stack-based buffer overflow was found in the way the NTP autokey protocol was implemented. When an NTP client decrypted a secret received from an NTP server, it could cause that client to crash.
Statement: This issue affects the versions of ntp as shipped with Red Hat Enterprise Linux 5.
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact
Debian
CVE-2015-7702: ntp - The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4...
vendor_debian·2015·CVSS 5.8
CVE-2015-7702 [MEDIUM] CVE-2015-7702: ntp - The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4...
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
Debian
CVE-2015-7692: ntp - The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4...
vendor_debian·2015·CVSS 5.8
CVE-2015-7692 [MEDIUM] CVE-2015-7692: ntp - The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4...
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
Debian
CVE-2015-7691: ntp - The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4...
vendor_debian·2015·CVSS 5.8
CVE-2015-7691 [MEDIUM] CVE-2015-7691: ntp - The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4...
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
Debian
CVE-2014-9750: ntp - ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is e...
vendor_debian·2014·CVSS 5.8
CVE-2014-9750 [MEDIUM] CVE-2014-9750: ntp - ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is e...
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field.
Scope: local
bullseye: resolved (fixed in 1:4.2.6.p5+dfsg-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7691 CVE-2015-7692 CVE-2015-7702 ntp: incomplete checks in ntp_crypto.c
bugzilla·2015-10-22·CVSS 5.8
CVE-2015-7691 [MEDIUM] CVE-2015-7691 CVE-2015-7692 CVE-2015-7702 ntp: incomplete checks in ntp_crypto.c
CVE-2015-7691 CVE-2015-7692 CVE-2015-7702 ntp: incomplete checks in ntp_crypto.c
It was found that the fix for CVE-2014-9750 was incomplete: three issues were found in the value length checks in ntp_crypto.c, where a packet with particular autokey operations that contained malicious data was not always being completely validated. Receipt of these packets can cause ntpd to crash.
Upstream patch:
https://github.com/ntp-project/ntp/commit/c4cd4aaf418f57f7225708a93bf48afb2bc9c1da
Mitigation:
Disable NTP autokey authentication by removing, or commenting out, all configuration directives beginning with the 'crypto' keyword in your ntp.conf file.
External References:
https://github.com/ntp-project/ntp/blob/stable/NEWS#L11
http://support.ntp.org/bin/view/Main/SecurityNotice#October_2015_NTP
Bugzilla
CVE-2014-9297 CVE-2014-9750 ntp: vallen in extension fields are not validated
bugzilla·2015-01-21·CVSS 5.8
CVE-2014-9297 [MEDIUM] CVE-2014-9297 CVE-2014-9750 ntp: vallen in extension fields are not validated
CVE-2014-9297 CVE-2014-9750 ntp: vallen in extension fields are not validated
It was reported [1] that ntp miss validation of vallen value, leading to various info leaks:
* ntpd/ntp_crypto.c:571
* ntpd/ntp_crypto.c:1162
* ntpd/ntp_crypto.c:1559
* ntpd/ntp_crypto.c:2117
* ntpd/ntp_crypto.c:1461
Upstream commits that fixes this:
http://bk.ntp.org/ntp-stable/?PAGE=patch&REV=5492d353ncauuWt_PONxaDhC5Qv_SA
http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=54abb266In81wLNAqIaovtP8f2UmUw
http://bk1.ntp.org/ntp-stable/?PAGE=patch&REV=54a7c595jlwS3KmAxBML75HFGLR_pQ
[1]: http://bugs.ntp.org/2671
Discussion:
*** Bug 1189406 has been marked as a duplicate of this bug. ***
---
External References:
http://support.ntp.org/bin/view/Main/SecurityNotice#vallen_is_not_validated_in_sever
---
ntp-4.2.6p
http://bugs.ntp.org/show_bug.cgi?id=2671http://rhn.redhat.com/errata/RHSA-2015-1459.htmlhttp://support.ntp.org/bin/view/Main/SecurityNotice#December_2014_NTP_Security_Vulnehttp://www.debian.org/security/2015/dsa-3388http://www.kb.cert.org/vuls/id/852879http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72583https://bugzilla.redhat.com/show_bug.cgi?id=1184573https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03886en_ushttp://bugs.ntp.org/show_bug.cgi?id=2671http://rhn.redhat.com/errata/RHSA-2015-1459.htmlhttp://support.ntp.org/bin/view/Main/SecurityNotice#December_2014_NTP_Security_Vulnehttp://www.debian.org/security/2015/dsa-3388http://www.kb.cert.org/vuls/id/852879http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72583https://bugzilla.redhat.com/show_bug.cgi?id=1184573https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03886en_us
2015-10-06
Published