cbcvebase.

Debian Ntp vulnerabilities

88 known vulnerabilities affecting debian/ntp.

Total CVEs
88
CISA KEV
0
Public exploits
7
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH24MEDIUM40LOW21

Vulnerabilities

Page 1 of 5
CVE-2013-5211P2LOWCVSS 5.0ExploitedPoCfixed in ntp 1:4.2.8p3+dfsg-1 (bullseye)2013
CVE-2013-5211 [MEDIUM] CVE-2013-5211: ntp - The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remot... The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013. Scope: local bullseye: resolved (fixed in 1:4.2.8p3+dfsg-1)
debian
CVE-2015-7871P1CRITICALCVSS 9.8PoCfixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7871 [CRITICAL] CVE-2015-7871: ntp - Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 ... Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. Scope: local bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
debian
CVE-2016-7434P3HIGHCVSS 7.5PoCfixed in ntp 1:4.2.8p9+dfsg-1 (bullseye)2016
CVE-2016-7434 [HIGH] CVE-2016-7434: ntp - The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to caus... The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query. Scope: local bullseye: resolved (fixed in 1:4.2.8p9+dfsg-1)
debian
CVE-2018-7182P3HIGHCVSS 7.5PoCfixed in ntp 1:4.2.8p11+dfsg-1 (bullseye)2018
CVE-2018-7182 [HIGH] CVE-2018-7182: ntp - The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote atta... The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10. Scope: local bullseye: resolved (fixed in 1:4.2.8p11+dfsg-1)
debian
CVE-2014-9295P2HIGHCVSS 7.5fixed in ntp 1:4.2.6.p5+dfsg-3.2 (bullseye)2014
CVE-2014-9295 [HIGH] CVE-2014-9295: ntp - Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote a... Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authentication feature is used, (2) the ctl_putdata function, and (3) the configure function. Scope: local bullseye: resolved (fixed in 1:4.2.6.p5+dfsg-3.2)
debian
CVE-2015-7855P3MEDIUMCVSS 6.5PoCfixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7855 [MEDIUM] CVE-2015-7855: ntp - The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before ... The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value. Scope: local bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
debian
CVE-2009-3563P3MEDIUMCVSS 6.4PoCfixed in ntp 1:4.2.4p8+dfsg-1 (bullseye)2009
CVE-2009-3563 [MEDIUM] CVE-2009-3563: ntp - ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers ... ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons. Scope: local bullseye: resolved (fixed in 1:4.2.4p8+dfsg-1)
debian
CVE-2016-0727P3LOWCVSS 7.8PoCfixed in ntp 1:4.2.8p9+dfsg-2 (bullseye)2016
CVE-2016-0727 [HIGH] CVE-2016-0727: ntp - The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubun... The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 16.04 LTS allows local users with access to the ntp account to write to arbitrary files and consequently gain privileges via vectors involving statistics d
debian
CVE-2015-7849P3HIGHCVSS 8.8fixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7849 [HIGH] CVE-2015-7849: ntp - Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x befo... Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets. Scope: local bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
debian
CVE-2018-7183P3LOWCVSS 9.8fixed in ntp 1:4.2.8p11+dfsg-1 (bullseye)2018
CVE-2018-7183 [CRITICAL] CVE-2018-7183: ntp - Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p1... Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array. Scope: local bullseye: resolved (fixed in 1:4.2.8p11+dfsg-1)
debian
CVE-2015-7853P3CRITICALCVSS 9.8fixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7853 [CRITICAL] CVE-2015-7853: ntp - The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.... The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative input value. Scope: local bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
debian
CVE-2015-7854P3HIGHCVSS 8.8fixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7854 [HIGH] CVE-2015-7854: ntp - Buffer overflow in the password management functionality in NTP 4.2.x before 4.2... Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted key file. Scope: local bullseye: resolved (fixed in 1:4.2.8p4+dfsg-1)
debian
CVE-2015-7705P3CRITICALCVSS 9.8fixed in ntp 1:4.2.8p4+dfsg-3 (bullseye)2015
CVE-2015-7705 [CRITICAL] CVE-2015-7705: ntp - The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allo... The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests. Scope: local bullseye: resolved (fixed in 1:4.2.8p4+dfsg-3)
debian
CVE-2016-4957P3MEDIUMCVSS 5.3fixed in ntp 1:4.2.8p8+dfsg-1 (bullseye)2016
CVE-2016-4957 [MEDIUM] CVE-2016-4957: ntp - ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service ... ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547. Scope: local bullseye: resolved (fixed in 1:4.2.8p8+dfsg-1)
debian
CVE-2009-1252P3HIGHCVSS 6.8fixed in ntp 1:4.2.4p6+dfsg-2 (bullseye)2009
CVE-2009-1252 [MEDIUM] CVE-2009-1252: ntp - Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd ... Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field. Scope: local bullseye: resolved (fixed in 1:4.2.4p6+dfsg-2)
debian
CVE-2017-6458P3LOWCVSS 8.8fixed in ntp 1:4.2.8p10+dfsg-1 (bullseye)2017
CVE-2017-6458 [HIGH] CVE-2017-6458: ntp - Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4... Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable. Scope: local bullseye: resolved (fixed in 1:4.2.8p10+dfsg-1)
debian
CVE-2016-4953P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p8+dfsg-1 (bullseye)2016
CVE-2016-4953 [HIGH] CVE-2016-4953: ntp - ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of serv... ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time. Scope: local bullseye: resolved (fixed in 1:4.2.8p8+dfsg-1)
debian
CVE-2015-7703P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7703 [HIGH] CVE-2015-7703: ntp - The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.... The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command. Scope: local bullsey
debian
CVE-2017-6460P3HIGHCVSS 8.8fixed in ntp 1:4.2.8p10+dfsg-1 (bullseye)2017
CVE-2017-6460 [HIGH] CVE-2017-6460: ntp - Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p... Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspecified impact via a long flagstr variable in a restriction list response. Scope: local bullseye: resolved (fixed in 1:4.2.8p10+dfsg-1)
debian
CVE-2015-7979P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p7+dfsg-1 (bullseye)2015
CVE-2015-7979 [HIGH] CVE-2015-7979: ntp - NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a de... NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by sending broadcast packets with invalid authentication to a broadcast client. Scope: local bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
debian
Debian Ntp vulnerabilities | cvebase