CVE-2019-8936NULL Pointer Dereference in HPE Hpux-ntp

Severity
7.5HIGHNVD
EPSS
23.9%
top 3.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 15
Latest updateMay 24

Description

NTP through 4.2.8p12 has a NULL Pointer Dereference.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

NVDntp/ntp< 4.2.8+1
NVDhpe/hpux-ntp< c.4.2.8.4.0
Debianntp/ntp< 1:4.2.8p12+dfsg-4
NVDopensuse/leap15.0, 42.3+1

Also affects: Fedora 28, 29, 30

Patches

🔴Vulnerability Details

3
GHSA
GHSA-54w8-prj8-6v5f: NTP through 42022-05-24
OSV
CVE-2019-8936: NTP through 42019-05-15
CVEList
CVE-2019-8936: NTP through 42019-05-15

📋Vendor Advisories

5
Ubuntu
NTP vulnerability2021-04-20
Ubuntu
NTP vulnerability2020-10-01
BSD
FreeBSD-SA-19:04.ntp: Authenticated denial of service in ntpd2019-05-14
Red Hat
ntp: Crafted null dereference attack in authenticated mode 6 packet2019-03-07
Debian
CVE-2019-8936: ntp - NTP through 4.2.8p12 has a NULL Pointer Dereference.2019

💬Community

2
Bugzilla
CVE-2019-8936 ntp: Crafted null dereference attack in authenticated mode 6 packet2019-03-07
Bugzilla
CVE-2019-8936 ntp: Crafted null dereference attack in authenticated mode 6 packet [fedora-all]2019-03-07