CVE-2009-3563
Summary
| CVE | CVE-2009-3563 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-09 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons. |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:N/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ntp | Ntp | 4.0.72 | All | All | All |
| Application | Ntp | Ntp | 4.0.73 | All | All | All |
| Application | Ntp | Ntp | 4.0.90 | All | All | All |
| Application | Ntp | Ntp | 4.0.91 | All | All | All |
| Application | Ntp | Ntp | 4.0.92 | All | All | All |
| Application | Ntp | Ntp | 4.0.93 | All | All | All |
| Application | Ntp | Ntp | 4.0.94 | All | All | All |
| Application | Ntp | Ntp | 4.0.95 | All | All | All |
| Application | Ntp | Ntp | 4.0.96 | All | All | All |
| Application | Ntp | Ntp | 4.0.97 | All | All | All |
| Application | Ntp | Ntp | 4.0.98 | All | All | All |
| Application | Ntp | Ntp | 4.0.99 | All | All | All |
| Application | Ntp | Ntp | 4.1.0 | All | All | All |
| Application | Ntp | Ntp | 4.1.2 | All | All | All |
| Application | Ntp | Ntp | 4.2.0 | All | All | All |
| Application | Ntp | Ntp | 4.2.2 | All | All | All |
| Application | Ntp | Ntp | 4.2.2p1 | All | All | All |
| Application | Ntp | Ntp | 4.2.2p2 | All | All | All |
| Application | Ntp | Ntp | 4.2.2p3 | All | All | All |
| Application | Ntp | Ntp | 4.2.5 | All | All | All |
| Application | Ntp | Ntp | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware ESX Server Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| aix.software.ibm.com/aix/efixes/security/xntpd_advisory.asc | af854a3a-2127-422b-91ae-364da2661108 | aix.software.ibm.com | |
| VMware vMA Update for Multiple Packages - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2010-005.txt.asc | af854a3a-2127-422b-91ae-364da2661108 | ftp.netbsd.org | |
| ASA-2009-591 (RHSA-2009-1648) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| NTP Mode 7 Request Denial of Service - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Juniper Networks - 2015-04 Security Bulletin: IDP: Multiple vulnerabilities addressed by third party software updates. | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| NTP mode 7 MODE_PRIVATE Packet Remote Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Debian -- Security Information -- DSA-1948-1 ntp | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch |
| '[security bulletin] HPSBUX02859 SSRT101144 rev.1 - HP-UX Running XNTP, Remote Denial of Service (DoS' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| US-CERT Vulnerability Note VU#568372 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Patch, US Government Resource |
| Cisco Systems, Inc. Information for VU#568372 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | |
| IBM IZ68659: NTP MODE 7 VULNERABILITY IN AIX 5.3 /AIX 6.1 APPLIES TO AIX 5300-08 - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Bug 1331 – DoS with mode 7 packets (CVE-2009-3563) | af854a3a-2127-422b-91ae-364da2661108 | support.ntp.org | |
| CVE-2009-3563 | af854a3a-2127-422b-91ae-364da2661108 | security-tracker.debian.org | |
| '[security bulletin] HPSBUX02639 SSRT100293 rev.1 - HP-UX Running XNTP, Remote Denial of Service (DoS' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 531213 – (CVE-2009-3563) CVE-2009-3563 ntpd: DoS with mode 7 packets (VU#568372) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| www.kb.cert.org/vuls/id/417980 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Avaya Products Two Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [Security-announce] VMSA-2010-0004 ESX Service Console and vMA third party updates | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | |
| [SECURITY] Fedora 10 Update: ntp-4.2.4p7-2.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| IBM AIX NTP Mode 7 Request Denial of Service - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| VMware ESX Server 4 Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| NetBSD update for ntp - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 11 Update: ntp-4.2.4p7-3.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| SecurityTracker.com Archives - NTP Mode 7 Packet Processing Flaw Lets Remote Users Deny Service | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| [ntp:announce] NTP 4.2.4p8 Released | af854a3a-2127-422b-91ae-364da2661108 | lists.ntp.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| access.redhat.com | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| #560074 - ntp: CVE-2009-3563 DoS through mode 7 packets - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| SecurityNotice < Main < NTP | af854a3a-2127-422b-91ae-364da2661108 | support.ntp.org | Patch |
| 2015-07 Security Bulletin: CTPView: Multiple vulnerabilities in CTPView - Juniper Networks | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| QNX Software Systems Inc. Information for VU#568372 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.