CVE-2017-6451
published 2017-03-27CVE-2017-6451: The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf…
PriorityP336high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.48%
38.8th percentile
The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which trigger an out-of-bounds memory write.
Affected
97 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_high_sierra | — | — |
| debian | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2017-6451: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 7.8
CVE-2017-6451 [HIGH] CVE-2017-6451: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-6451
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
Red Hat
ntp: Improper use of snprintf() in mx4200_send()
vendor_redhat·2017-03-21·CVSS 7.8
CVE-2017-6451 [HIGH] CWE-121 ntp: Improper use of snprintf() in mx4200_send()
ntp: Improper use of snprintf() in mx4200_send()
The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which trigger an out-of-bounds memory write.
A vulnerability was found in NTP, in the legacy MX4200 refclock implementation. If this refclock was compiled in and used, an attacker may be able to induce stack overflow, leading to a crash or potential code execution.
Mitigation: Properly monitor your ntpd instances, and auto-restart ntpd (without -g) if it stops running.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) - Not affected
Package: ntp
Debian
CVE-2017-6451: ntp - The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 an...
vendor_debian·2017·CVSS 7.8
CVE-2017-6451 [HIGH] CVE-2017-6451: ntp - The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 an...
The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which trigger an out-of-bounds memory write.
Scope: local
bullseye: resolved
GHSA
GHSA-mg4x-c4g8-f6h5: The mx4200_send function in the legacy MX4200 refclock in NTP before 4
ghsa_unreviewed·2022-05-17
CVE-2017-6451 [HIGH] CWE-787 GHSA-mg4x-c4g8-f6h5: The mx4200_send function in the legacy MX4200 refclock in NTP before 4
The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which trigger an out-of-bounds memory write.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-6464 CVE-2017-6462 CVE-2017-6463 CVE-2017-6458 CVE-2017-6451 ntp: various flaws [fedora-all]
bugzilla·2017-03-23·CVSS 7.8
CVE-2017-6464 [HIGH] CVE-2017-6464 CVE-2017-6462 CVE-2017-6463 CVE-2017-6458 CVE-2017-6451 ntp: various flaws [fedora-all]
CVE-2017-6464 CVE-2017-6462 CVE-2017-6463 CVE-2017-6458 CVE-2017-6451 ntp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2017-6451 ntp: Improper use of snprintf() in mx4200_send()
bugzilla·2017-03-20·CVSS 7.8
CVE-2017-6451 [HIGH] CVE-2017-6451 ntp: Improper use of snprintf() in mx4200_send()
CVE-2017-6451 ntp: Improper use of snprintf() in mx4200_send()
The legacy MX4200 refclock is only built if it is specifically enabled, and furthermore additional code changes are required to compile and use it. But it uses the libc functions snprintf() and vsnprintf() incorrectly, which can lead to an out-of-bounds memory write due to an improper handling of the return value of snprintf()/vsnprintf(). Since the return value is used as an iterator and it can be larger than the buffer's size, it is possible for the iterator to point somewhere outside of the allocated buffer space. This results in an out-of-bound memory write. This behavior can be leveraged to overwrite a saved instruction pointer on the stack and gain control over the execution flow.
During testing it was not possible to i
http://support.ntp.org/bin/view/Main/NtpBug3378http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secuhttp://www.securityfocus.com/bid/97058http://www.securitytracker.com/id/1038123http://www.securitytracker.com/id/1039427https://support.apple.com/HT208144https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_ushttp://support.ntp.org/bin/view/Main/NtpBug3378http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secuhttp://www.securityfocus.com/bid/97058http://www.securitytracker.com/id/1038123http://www.securitytracker.com/id/1039427https://support.apple.com/HT208144https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us
2017-03-27
Published