cbcvebase.

Debian Ntp vulnerabilities

88 known vulnerabilities affecting debian/ntp.

Total CVEs
88
CISA KEV
0
Public exploits
7
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH24MEDIUM40LOW21

Vulnerabilities

Page 2 of 5
CVE-2009-0159P3LOWCVSS 6.8fixed in ntp 1:4.2.4p6+dfsg-2 (bullseye)2009
CVE-2009-0159 [MEDIUM] CVE-2009-0159: ntp - Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq i... Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response. Scope: local bullseye: resolved (fixed in 1:4.2.4p6+dfsg-2)
debian
CVE-2015-7974P3LOWCVSS 7.7fixed in ntp 1:4.2.8p7+dfsg-1 (bullseye)2015
CVE-2015-7974 [HIGH] CVE-2015-7974: ntp - NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations o... NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key." Scope: local bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
debian
CVE-2015-5300P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p4+dfsg-2 (bullseye)2015
CVE-2015-5300 [HIGH] CVE-2015-5300: ntp - The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first ch... The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources
debian
CVE-2014-9293P3HIGHCVSS 7.5fixed in ntp 1:4.2.6.p5+dfsg-3.2 (bullseye)2014
CVE-2014-9293 [HIGH] CVE-2014-9293: ntp - The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not... The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. Scope: local bullseye: resolved (fixed in 1:4.2.6.p5+dfsg-3.2)
debian
CVE-2014-9294P3HIGHCVSS 7.5fixed in ntp 1:4.2.6.p5+dfsg-3.2 (bullseye)2014
CVE-2014-9294 [HIGH] CVE-2014-9294: ntp - util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, wh... util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. Scope: local bullseye: resolved (fixed in 1:4.2.6.p5+dfsg-3.2)
debian
CVE-2015-7704P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p4+dfsg-3 (bullseye)2015
CVE-2015-7704 [HIGH] CVE-2015-7704: ntp - The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote ... The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages. Scope: local bullseye: resolved (fixed in 1:4.2.8p4+dfsg-3)
debian
CVE-2016-4954P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p8+dfsg-1 (bullseye)2016
CVE-2016-4954 [HIGH] CVE-2016-4954: ntp - The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 all... The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication. Scope: local bullseye: resolved (fixed in 1:4.2.8p8+dfsg-1)
debian
CVE-2015-3405P3HIGHCVSS 7.5fixed in ntp 1:4.2.6.p5+dfsg-7 (bullseye)2015
CVE-2015-3405 [HIGH] CVE-2015-3405: ntp - ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not ge... ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys. Scope: local bulls
debian
CVE-2016-9310P3MEDIUMCVSS 6.5fixed in ntp 1:4.2.8p9+dfsg-1 (bullseye)2016
CVE-2016-9310 [MEDIUM] CVE-2016-9310: ntp - The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows rem... The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet. Scope: local bullseye: resolved (fixed in 1:4.2.8p9+dfsg-1)
debian
CVE-2016-7426P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p9+dfsg-1 (bullseye)2016
CVE-2016-7426 [HIGH] CVE-2016-7426: ntp - NTP before 4.2.8p9 rate limits responses received from the configured sources wh... NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address. Scope: local bullseye: resolved (fixed in 1:4.2.8p9+dfsg-1)
debian
CVE-2015-7848P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p4+dfsg-1 (bullseye)2015
CVE-2015-7848 [HIGH] CVE-2015-7848: ntp - An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memo... An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authentication code and a valid timestamp. When processed by the NTP daemon, it leads to an immediate crash. Scope: local bullseye: resolved (fixed in 1:4.2.8p4+dfsg-
debian
CVE-2015-7978P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p7+dfsg-1 (bullseye)2015
CVE-2015-7978 [HIGH] CVE-2015-7978: ntp - NTP before 4.2.8p6 and 4.3.0 before 4.3.90 allows a remote attackers to cause a ... NTP before 4.2.8p6 and 4.3.0 before 4.3.90 allows a remote attackers to cause a denial of service (stack exhaustion) via an ntpdc relist command, which triggers recursive traversal of the restriction list. Scope: local bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
debian
CVE-2020-13817P3LOWCVSS 7.4fixed in ntp 1:4.2.8p14+dfsg-1 (bullseye)2020
CVE-2020-13817 [HIGH] CVE-2020-13817: ntp - ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to ... ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance. Scope: local bul
debian
CVE-2014-9296P3MEDIUMCVSS 5.0fixed in ntp 1:4.2.6.p5+dfsg-3.2 (bullseye)2014
CVE-2014-9296 [MEDIUM] CVE-2014-9296: ntp - The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to exe... The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to execute after detecting a certain authentication error, which might allow remote attackers to trigger an unintended association change via crafted packets. Scope: local bullseye: resolved (fixed in 1:4.2.6.p5+dfsg-3.2)
debian
CVE-2016-1548P3HIGHCVSS 7.2fixed in ntp 1:4.2.8p7+dfsg-1 (bullseye)2016
CVE-2016-1548 [HIGH] CVE-2016-1548: ntp - An attacker can spoof a packet from a legitimate ntpd server with an origin time... An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time a
debian
CVE-2018-7185P3LOWCVSS 7.5fixed in ntp 1:4.2.8p11+dfsg-1 (bullseye)2018
CVE-2018-7185 [HIGH] CVE-2018-7185: ntp - The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to ca... The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association. Scope: local bullseye: resolved (fixed in 1:4.2.8p11+dfsg-1)
debian
CVE-2018-7184P3LOWCVSS 7.5fixed in ntp 1:4.2.8p11+dfsg-1 (bullseye)2018
CVE-2018-7184 [HIGH] CVE-2018-7184: ntp - ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "recei... ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-201
debian
CVE-2015-5195P3LOWCVSS 7.5fixed in ntp 1:4.2.8p3+dfsg-1 (bullseye)2015
CVE-2015-5195 [HIGH] CVE-2015-5195: ntp - ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause ... ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation. Scope: local bullseye: resolved (fixed in 1:4.2.8p3+dfsg-1)
debian
CVE-2020-11868P3HIGHCVSS 7.5fixed in ntp 1:4.2.8p14+dfsg-1 (bullseye)2020
CVE-2020-11868 [HIGH] CVE-2020-11868: ntp - ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker... ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp. Scope: local bullseye: resolved (fixed in 1:4.2.8p14+dfsg-1)
debian
CVE-2015-5194P3LOWCVSS 7.5fixed in ntp 1:4.2.8p3+dfsg-1 (bullseye)2015
CVE-2015-5194 [HIGH] CVE-2015-5194: ntp - The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 a... The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands. Scope: local bullseye: resolved (fixed in 1:4.2.8p3+dfsg-1)
debian
Debian Ntp vulnerabilities | cvebase