Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3.12 Ntp_advisory9 | — | — | Jul 21, 2017 | Mar 27, 2017 |
| Aix 6.1.6 Ntp_advisory9 | — | — | Jul 21, 2017 | Mar 27, 2017 |
| Aix 6.1.9 Ntp_advisory9 | — | — | Jul 21, 2017 | Mar 27, 2017 |
| Aix 7.1.0 Ntp_advisory9 | — | — | Jul 21, 2017 | Mar 27, 2017 |
| Aix 7.1.3 Ntp_advisory9 | — | — | Jul 21, 2017 | Mar 27, 2017 |
| Aix 7.1.4 Ntp_advisory9 | — | — | Jul 21, 2017 | Mar 27, 2017 |
| Aix 7.2.0 Ntp_advisory9 | — | — | Jul 21, 2017 | Mar 27, 2017 |
| Aix 7.2.1 Ntp_advisory9 | — | — | Jul 21, 2017 | Mar 27, 2017 |
| Amazon_linux | — | Upgrade ntp | Apr 20, 2017 | Mar 27, 2017 |
| Apple Osx Ntp | — | Upgrade macOS to the latest version | Sep 26, 2017 | Mar 27, 2017 |
| Debian | — | Upgrade ntp | Jul 30, 2024 | Mar 27, 2017 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | May 8, 2017 |
| Hpux | — | Update NTP to the latest version | Dec 9, 2019 | Mar 27, 2017 |
| Ibm Aix | — | Apply the fix or workaround for ntp_advisory9 | Nov 3, 2017 | Mar 27, 2017 |
| Ntp | — | Upgrade NTP to version 4.2.8Upgrade NTP to version 4.3.94 | Feb 23, 2023 | Mar 27, 2017 |
| Oracle Solaris | — | Upgrade service/network/ntp to version 4.2.8.10-0.175.3.20.0.2.0 on Solaris 11.3 | Jun 8, 2017 | Mar 27, 2017 |
| Suse | — | Upgrade ntpUpgrade ntp-doc | Apr 19, 2017 | Mar 27, 2017 |
| Ubuntu | — | Upgrade ntp | Jul 6, 2017 | Mar 27, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 27, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub