CVE Vulnerabilities

CVE-2009-3563

Published: Dec 09, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.

Affected Software

NameVendorStart VersionEnd Version
NtpNtp*4.2.2p4 (including)
NtpNtp4.0.72 (including)4.0.72 (including)
NtpNtp4.0.73 (including)4.0.73 (including)
NtpNtp4.0.90 (including)4.0.90 (including)
NtpNtp4.0.91 (including)4.0.91 (including)
NtpNtp4.0.92 (including)4.0.92 (including)
NtpNtp4.0.93 (including)4.0.93 (including)
NtpNtp4.0.94 (including)4.0.94 (including)
NtpNtp4.0.95 (including)4.0.95 (including)
NtpNtp4.0.96 (including)4.0.96 (including)
NtpNtp4.0.97 (including)4.0.97 (including)
NtpNtp4.0.98 (including)4.0.98 (including)
NtpNtp4.0.99 (including)4.0.99 (including)
NtpNtp4.1.0 (including)4.1.0 (including)
NtpNtp4.1.2 (including)4.1.2 (including)
NtpNtp4.2.0 (including)4.2.0 (including)
NtpNtp4.2.2 (including)4.2.2 (including)
NtpNtp4.2.2p1 (including)4.2.2p1 (including)
NtpNtp4.2.2p2 (including)4.2.2p2 (including)
NtpNtp4.2.2p3 (including)4.2.2p3 (including)
NtpNtp4.2.5 (including)4.2.5 (including)
Red Hat Enterprise Linux 3RedHatntp-0:4.1.2-6.el3*
Red Hat Enterprise Linux 4RedHatntp-0:4.2.0.a.20040617-8.el4_8.1*
Red Hat Enterprise Linux 5RedHatntp-0:4.2.2p1-9.el5_4.1*
NtpUbuntudapper*
NtpUbuntudevel*
NtpUbuntuhardy*
NtpUbuntuintrepid*
NtpUbuntujaunty*
NtpUbuntukarmic*
NtpUbuntuupstream*

References