CVE-2017-6458
published 2017-03-27CVE-2017-6458: Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact…
PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
6.51%
93.0th percentile
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | >= 10.8.0 < 10.13 | 10.13 |
| apple | macos_high_sierra | — | — |
| debian | ntp | < ntp 1:4.2.8p10+dfsg-1 (bullseye) | ntp 1:4.2.8p10+dfsg-1 (bullseye) |
| hpe | hpux-ntp | < c.4.2.8.4.0 | c.4.2.8.4.0 |
| ntp | ntp | < 4.2.8 | 4.2.8 |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p10+dfsg-1 | 1:4.2.8p10+dfsg-1 |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.11 | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.11 |
| ntp | ntp | >= 0 < 1:4.2.8p4+dfsg-3ubuntu5.5 | 1:4.2.8p4+dfsg-3ubuntu5.5 |
| ntp | ntp | >= 4.3.0 < 4.3.94 | 4.3.94 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC NET CP 443-1 OPC UA
cisa_ics·2021-06-08·CVSS 5.9
[MEDIUM] Siemens SIMATIC NET CP 443-1 OPC UA
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC NET CP 443-1 OPC UA
Last RevisedJune 08, 2021
Alert CodeICSA-21-159-11
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC NET CP 443-1 OPC UA
- Vulnerabilities: Improper Input Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, Incorrect Calculation, Classic Buffer Overflow, Improper Authentication, Race Condition, Data Processing Errors, Exposure of Sensitive Information to an Unauthorized Actor, Out-of-bounds Read
## 2. RISK EVALUATION
Succes
Apple
CVE-2017-6458: macOS High Sierra 10.13
vendor_apple·2017-09-25·CVSS 8.8
CVE-2017-6458 [HIGH] CVE-2017-6458: macOS High Sierra 10.13
Apple Security Update: About the security content of macOS High Sierra 10.13
Product: macOS High Sierra
Version: 10.13
CVE: CVE-2017-6458
Component: Mail Drafts
Impact: An attacker with a privileged network position may be able to intercept mail contents
Description: An encryption issue existed in the handling of mail drafts. This issue was addressed with improved handling of mail drafts meant to be sent encrypted.
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2017-07-05·CVSS 5.9
CVE-2016-2519 [MEDIUM] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Yihan Lian discovered that NTP incorrectly handled certain large request
data values. A remote attacker could possibly use this issue to cause NTP
to crash, resulting in a denial of service. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-2519)
Miroslav Lichvar discovered that NTP incorrectly handled certain spoofed
addresses when performing rate limiting. A remote attacker could possibly
use this issue to perform a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2016-7426)
Matthew Van Gundy discovered that NTP incorrectly handled certain crafted
broadcast mode packets. A remote attacker could possibly use this issue to
perform a denial of service.
Red Hat
ntp: Potential Overflows in ctl_put() functions
vendor_redhat·2017-03-21·CVSS 8.8
CVE-2017-6458 [HIGH] CWE-121 ntp: Potential Overflows in ctl_put() functions
ntp: Potential Overflows in ctl_put() functions
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
A vulnerability was found in NTP, in the building of response packets with custom fields. If custom fields were configured in ntp.conf with particularly long names, inclusion of these fields in the response packet could cause a buffer overflow, leading to a crash.
Statement: The security assessment from cure53 clarifies that this issue (identified as NTP-01-0004) is not a vulnerability per se, but a weakness in ntp's internal coding style that may cause a vulnerability if particularly long variable names are defined at compile time. No such variable names are def
Debian
CVE-2017-6458: ntp - Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4...
vendor_debian·2017·CVSS 8.8
CVE-2017-6458 [HIGH] CVE-2017-6458: ntp - Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4...
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p10+dfsg-1)
GHSA
GHSA-q29q-rg5m-wg5j: Multiple buffer overflows in the ctl_put* functions in NTP before 4
ghsa_unreviewed·2022-05-13
CVE-2017-6458 [HIGH] CWE-119 GHSA-q29q-rg5m-wg5j: Multiple buffer overflows in the ctl_put* functions in NTP before 4
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
OSV
ntp vulnerabilities
osv·2017-07-05·CVSS 5.9
CVE-2016-2519 [MEDIUM] ntp vulnerabilities
ntp vulnerabilities
Yihan Lian discovered that NTP incorrectly handled certain large request
data values. A remote attacker could possibly use this issue to cause NTP
to crash, resulting in a denial of service. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-2519)
Miroslav Lichvar discovered that NTP incorrectly handled certain spoofed
addresses when performing rate limiting. A remote attacker could possibly
use this issue to perform a denial of service. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 16.10. (CVE-2016-7426)
Matthew Van Gundy discovered that NTP incorrectly handled certain crafted
broadcast mode packets. A remote attacker could possibly use this issue to
perform a denial of service. This issue only affected Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS,
OSV
CVE-2017-6458: Multiple buffer overflows in the ctl_put* functions in NTP before 4
osv·2017-03-27·CVSS 8.8
CVE-2017-6458 [HIGH] CVE-2017-6458: Multiple buffer overflows in the ctl_put* functions in NTP before 4
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-6464 CVE-2017-6462 CVE-2017-6463 CVE-2017-6458 CVE-2017-6451 ntp: various flaws [fedora-all]
bugzilla·2017-03-23·CVSS 7.8
CVE-2017-6464 [HIGH] CVE-2017-6464 CVE-2017-6462 CVE-2017-6463 CVE-2017-6458 CVE-2017-6451 ntp: various flaws [fedora-all]
CVE-2017-6464 CVE-2017-6462 CVE-2017-6463 CVE-2017-6458 CVE-2017-6451 ntp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2017-6458 ntp: Potential Overflows in ctl_put() functions
bugzilla·2017-03-20·CVSS 8.8
CVE-2017-6458 [HIGH] CVE-2017-6458 ntp: Potential Overflows in ctl_put() functions
CVE-2017-6458 ntp: Potential Overflows in ctl_put() functions
ntpd makes use of different wrappers around ctl_putdata() to create name/value ntpq (mode 6) response strings. For example, ctl_putstr() is usually used to send string data (variable names or string data). The formatting code was missing a length check for variable names. If somebody explicitly created any unusually long variable names in ntpd (longer than 200-512 bytes, depending on the type of variable), then if any of these variables are added to the response list it would overflow a buffer.
Mitigation:
Implement BCP-38.
If you don't want to upgrade, then don't setvar variable names longer than 200-512 bytes in your ntp.conf file.
Properly monitor your ntpd instances, and auto-restart ntpd (without -g) if it stops runnin
http://packetstormsecurity.com/files/142284/Slackware-Security-Advisory-ntp-Updates.htmlhttp://seclists.org/fulldisclosure/2017/Nov/7http://seclists.org/fulldisclosure/2017/Sep/62http://support.ntp.org/bin/view/Main/NtpBug3379http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secuhttp://www.securityfocus.com/archive/1/archive/1/540464/100/0/threadedhttp://www.securityfocus.com/bid/97051http://www.securitytracker.com/id/1038123http://www.ubuntu.com/usn/USN-3349-1https://bto.bluecoat.com/security-advisory/sa147https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4B7BMVXV53EE7XYW2KAVETDHTP452O3Z/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7KVLFA3J43QFIP4I7HE7KQ5FXSMJEKC6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZUPPICJXWL3AWQB7I3AWUC74YON7UING/https://support.apple.com/HT208144https://support.apple.com/kb/HT208144https://support.f5.com/csp/article/K99254031https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_ushttps://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-294/http://packetstormsecurity.com/files/142284/Slackware-Security-Advisory-ntp-Updates.htmlhttp://seclists.org/fulldisclosure/2017/Nov/7http://seclists.org/fulldisclosure/2017/Sep/62http://support.ntp.org/bin/view/Main/NtpBug3379http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secuhttp://www.securityfocus.com/archive/1/archive/1/540464/100/0/threadedhttp://www.securityfocus.com/bid/97051http://www.securitytracker.com/id/1038123http://www.ubuntu.com/usn/USN-3349-1https://bto.bluecoat.com/security-advisory/sa147https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4B7BMVXV53EE7XYW2KAVETDHTP452O3Z/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7KVLFA3J43QFIP4I7HE7KQ5FXSMJEKC6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZUPPICJXWL3AWQB7I3AWUC74YON7UING/https://support.apple.com/HT208144https://support.apple.com/kb/HT208144https://support.f5.com/csp/article/K99254031https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_ushttps://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-294/
2017-03-27
Published