ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (ntpd abort) by a large request data value, which triggers the ctl_getitem function to return a NULL value.
CVSS Details
- CVSS 3.0 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cisco Apic | cisco-apic-update-latest | May 11, 2026 | Apr 28, 2016 | |
| Debian | debian-upgrade-ntp | Jul 30, 2024 | Jan 30, 2017 | |
| F5 Big Ip | f5-bigip-upgrade-latest | Jun 17, 2026 | May 26, 2016 | |
| Freebsd | freebsd-upgrade-package-ntpfreebsd-upgrade-package-ntp-develfreebsd-upgrade-base-10_3-release-p1freebsd-upgrade-base-10_2-release-p15freebsd-upgrade-base-10_1-release-p32freebsd-upgrade-base-9_3-release-p40 | Dec 10, 2025 | Apr 27, 2016 | |
| Gentoo Linux | gentoo-linux-upgrade-net-misc-ntp | Oct 30, 2017 | Jan 30, 2017 | |
| Ibm Aix | ibm-aix-ntp_advisory7 | Nov 30, 2017 | Jan 30, 2017 | |
| Ntp | ntp-upgrade-latest | Feb 23, 2023 | Jan 30, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-service-network-ntp-4-2-8-8-0-175-3-12-0-1-0 | May 29, 2017 | Jan 30, 2017 | |
| Suse | — | suse-upgrade-ntpsuse-upgrade-ntp-doc | May 11, 2016 | May 11, 2016 |
| Ubuntu | ubuntu-upgrade-ntp | Jul 6, 2017 | May 11, 2016 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jan 30, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub