CVE-2014-9751
published 2015-10-06CVE-2014-9751: The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an…
PriorityP337medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.53%
90.6th percentile
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ntp | < ntp 1:4.2.6.p5+dfsg-4 (bullseye) | ntp 1:4.2.6.p5+dfsg-4 (bullseye) |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-4 | 1:4.2.6.p5+dfsg-4 |
| ntp | ntp | >= 4.2.0 < 4.2.8 | 4.2.8 |
| oracle | linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ffj6-rf7h-c479: The read_network_packet function in ntp_io
ghsa_unreviewed·2022-05-13
CVE-2014-9751 [MEDIUM] CWE-20 GHSA-ffj6-rf7h-c479: The read_network_packet function in ntp_io
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.
OSV
CVE-2014-9751: The read_network_packet function in ntp_io
osv·2015-10-06·CVSS 6.8
CVE-2014-9751 [MEDIUM] CVE-2014-9751: The read_network_packet function in ntp_io
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.
Red Hat
ntp: drop packets with source address ::1
vendor_redhat·2015-02-04·CVSS 6.8
CVE-2014-9751 [MEDIUM] ntp: drop packets with source address ::1
ntp: drop packets with source address ::1
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.
It was found that because NTP's access control was based on a source IP address, an attacker could bypass source IP restrictions and send malicious control and configuration packets by spoofing ::1 addresses.
Statement: This issue affects the versions of ntp as shipped with Red Hat Enterprise Linux 5.
Red Hat Enterprise Linux 5 is now in Production 3
Debian
CVE-2014-9751: ntp - The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 o...
vendor_debian·2014·CVSS 6.8
CVE-2014-9751 [MEDIUM] CVE-2014-9751: ntp - The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 o...
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.
Scope: local
bullseye: resolved (fixed in 1:4.2.6.p5+dfsg-4)
No detection rules found.
No public exploits indexed.
http://bugs.ntp.org/show_bug.cgi?id=2672http://rhn.redhat.com/errata/RHSA-2015-1459.htmlhttp://support.ntp.org/bin/view/Main/SecurityNotice#December_2014_NTP_Security_Vulnehttp://www.debian.org/security/2015/dsa-3388http://www.kb.cert.org/vuls/id/852879http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72584https://bugzilla.redhat.com/show_bug.cgi?id=1184572https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03886en_ushttp://bugs.ntp.org/show_bug.cgi?id=2672http://rhn.redhat.com/errata/RHSA-2015-1459.htmlhttp://support.ntp.org/bin/view/Main/SecurityNotice#December_2014_NTP_Security_Vulnehttp://www.debian.org/security/2015/dsa-3388http://www.kb.cert.org/vuls/id/852879http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72584https://bugzilla.redhat.com/show_bug.cgi?id=1184572https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03886en_us
2015-10-06
Published