CVE-2009-1252

UnknownEPSS 21.12%

Last modified

CVE-2009-1252 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.. EPSS estimates a 21.12% chance of exploitation in the next 30 days.

Description

Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

Metrics

EPSS Probability
21.12%

97.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NtpNtp4.2.4p0
NtpNtp4.2.4p1
NtpNtp4.2.4p2
NtpNtp4.2.4p3
NtpNtp4.2.4p4
NtpNtp4.2.4p5
NtpNtp4.2.4p6
NtpNtp4.2.5p0
NtpNtp4.2.5p1
NtpNtp4.2.5p2
NtpNtp4.2.5p3
NtpNtp4.2.5p4
NtpNtp4.2.5p5
NtpNtp4.2.5p6
NtpNtp4.2.5p7
NtpNtp4.2.5p8
NtpNtp4.2.5p9
NtpNtp4.2.5p10
NtpNtp4.2.5p11
NtpNtp4.2.5p12
NtpNtp4.2.5p13
NtpNtp4.2.5p14
NtpNtp4.2.5p15
NtpNtp4.2.5p16
NtpNtp4.2.5p17
NtpNtp4.2.5p18
NtpNtp4.2.5p19
NtpNtp4.2.5p20
NtpNtp4.2.5p21
NtpNtp4.2.5p23
NtpNtp4.2.5p24
NtpNtp4.2.5p25
NtpNtp4.2.5p26
NtpNtp4.2.5p27
NtpNtp4.2.5p28
NtpNtp4.2.5p29
NtpNtp4.2.5p30
NtpNtp4.2.5p31
NtpNtp4.2.5p32
NtpNtp4.2.5p33
NtpNtp4.2.5p35
NtpNtp4.2.5p36
NtpNtp4.2.5p37
NtpNtp4.2.5p38
NtpNtp4.2.5p39
NtpNtp4.2.5p40
NtpNtp4.2.5p41
NtpNtp4.2.5p42
NtpNtp4.2.5p43
NtpNtp4.2.5p44

Showing 50 of 78 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-1252?
Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.
How severe is CVE-2009-1252?
Severity scoring for CVE-2009-1252 is pending analysis. The EPSS model estimates a 21.12% probability of exploitation in the next 30 days.
How do I fix CVE-2009-1252?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-1252?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST