The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ntp | Ntp | * | 4.2.8 (excluding) |
Ntp | Ntp | 4.3.0 (including) | 4.3.92 (excluding) |
Ntp | Ntp | 4.2.8 (including) | 4.2.8 (including) |
Ntp | Ntp | 4.2.8-p1 (including) | 4.2.8-p1 (including) |
Ntp | Ntp | 4.2.8-p1-beta1 (including) | 4.2.8-p1-beta1 (including) |
Ntp | Ntp | 4.2.8-p1-beta2 (including) | 4.2.8-p1-beta2 (including) |
Ntp | Ntp | 4.2.8-p1-beta3 (including) | 4.2.8-p1-beta3 (including) |
Ntp | Ntp | 4.2.8-p1-beta4 (including) | 4.2.8-p1-beta4 (including) |
Ntp | Ntp | 4.2.8-p1-beta5 (including) | 4.2.8-p1-beta5 (including) |
Ntp | Ntp | 4.2.8-p1-rc1 (including) | 4.2.8-p1-rc1 (including) |
Ntp | Ntp | 4.2.8-p1-rc2 (including) | 4.2.8-p1-rc2 (including) |
Ntp | Ntp | 4.2.8-p2 (including) | 4.2.8-p2 (including) |
Ntp | Ntp | 4.2.8-p2-rc1 (including) | 4.2.8-p2-rc1 (including) |
Ntp | Ntp | 4.2.8-p2-rc2 (including) | 4.2.8-p2-rc2 (including) |
Ntp | Ntp | 4.2.8-p2-rc3 (including) | 4.2.8-p2-rc3 (including) |
Ntp | Ntp | 4.2.8-p3 (including) | 4.2.8-p3 (including) |
Ntp | Ntp | 4.2.8-p3-rc1 (including) | 4.2.8-p3-rc1 (including) |
Ntp | Ntp | 4.2.8-p3-rc2 (including) | 4.2.8-p3-rc2 (including) |
Ntp | Ntp | 4.2.8-p3-rc3 (including) | 4.2.8-p3-rc3 (including) |
Ntp | Ntp | 4.2.8-p4 (including) | 4.2.8-p4 (including) |
Ntp | Ntp | 4.2.8-p5 (including) | 4.2.8-p5 (including) |
Ntp | Ntp | 4.2.8-p6 (including) | 4.2.8-p6 (including) |
Ntp | Ntp | 4.2.8-p7 (including) | 4.2.8-p7 (including) |
Ntp | Ntp | 4.2.8-p8 (including) | 4.2.8-p8 (including) |
Red Hat Enterprise Linux 6 | RedHat | ntp-0:4.2.6p5-10.el6.1 | * |
Red Hat Enterprise Linux 6.7 Extended Update Support | RedHat | ntp-0:4.2.6p5-5.el6_7.5 | * |
Red Hat Enterprise Linux 7 | RedHat | ntp-0:4.2.6p5-22.el7_2.2 | * |
Ntp | Ubuntu | precise | * |
Ntp | Ubuntu | trusty | * |
Ntp | Ubuntu | upstream | * |
Ntp | Ubuntu | vivid/stable-phone-overlay | * |
Ntp | Ubuntu | wily | * |
Ntp | Ubuntu | xenial | * |