CVE-2009-1252
CVE-2009-1252
Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-006.txt.aschttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1039.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1040.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=499694http://secunia.com/advisories/35137http://secunia.com/advisories/35138http://secunia.com/advisories/35166http://secunia.com/advisories/35169http://secunia.com/advisories/35243http://secunia.com/advisories/35253http://secunia.com/advisories/35308