cbcvebase.
CVE-2017-6458
published 2017-03-27

CVE-2017-6458: Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact…

PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
6.51%
93.0th percentile
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.

Affected

10 ranges
VendorProductVersion rangeFixed in
applemac_os_x>= 10.8.0 < 10.1310.13
applemacos_high_sierra
debianntp< ntp 1:4.2.8p10+dfsg-1 (bullseye)ntp 1:4.2.8p10+dfsg-1 (bullseye)
hpehpux-ntp< c.4.2.8.4.0c.4.2.8.4.0
ntpntp< 4.2.84.2.8
ntpntp
ntpntp>= 0 < 1:4.2.8p10+dfsg-11:4.2.8p10+dfsg-1
ntpntp>= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.111:4.2.6.p5+dfsg-3ubuntu2.14.04.11
ntpntp>= 0 < 1:4.2.8p4+dfsg-3ubuntu5.51:4.2.8p4+dfsg-3ubuntu5.5
ntpntp>= 4.3.0 < 4.3.944.3.94

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.