The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, which allows an attacker to cause a denial of service (application crash).
CVSS Details
- CVSS 3.0 Base Score: 6.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cisco Apic | — | Upgrade to the latest version of Cisco APIC to resolve this vulnerability. | May 11, 2026 | Jan 27, 2016 |
| Cisco Ise | — | — | Oct 21, 2025 | Jan 27, 2016 |
| Cisco Xe | — | Upgrade to the latest version of Cisco IOS XE | Jul 30, 2019 | Jan 30, 2017 |
| Cisco Xr Os | — | Upgrade to the latest version of Cisco IOS-XR to resolve this vulnerability. | May 19, 2021 | Jan 27, 2016 |
| Debian | — | Upgrade ntp | Jul 30, 2024 | Jan 30, 2017 |
| Freebsd | — | Upgrade FreeBSDUpgrade ntp-develUpgrade ntp | Dec 10, 2025 | Jan 21, 2016 |
| Gentoo Linux | — | Upgrade net-misc/ntp. | Oct 30, 2017 | Jan 30, 2017 |
| Ntp | — | Upgrade to the latest version of NTP | Feb 23, 2023 | Jan 30, 2017 |
| Oracle Solaris | — | Upgrade service/network/ntp to version 4.2.8.6-0.175.3.6.0.1.0 on Solaris 11.3 | May 29, 2017 | Jan 30, 2017 |
| Panos | — | Update PAN-OS 6.1 to the latest workaround for your deviceUpdate PAN-OS 6.0 to the latest workaround for your deviceUpdate PAN-OS 5.0 to the latest workaround for your deviceUpdate PAN-OS 5.1 to the latest workaround for your deviceUpgrade PAN-OS 7.0 to the latest versionUpdate PAN-OS 7.1 to the latest workaround for your device | Oct 11, 2016 | Apr 28, 2016 |
| Suse | — | Upgrade ntp-docUpgrade yast2-ntp-client-devel-docUpgrade yast2-ntp-clientUpgrade ntp | Apr 28, 2016 | Apr 28, 2016 |
| Ubuntu | — | Upgrade ntp | Oct 7, 2016 | Apr 28, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub