CVE-2014-9751
Summary
| CVE | CVE-2014-9751 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-10-06 01:59:00 UTC |
| Updated | 2021-09-08 17:19:00 UTC |
| Description | The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Bug 2672 – ::1 can be spoofed. ACLs based on source IP can be bypassed |
CONFIRM |
bugs.ntp.org |
Issue Tracking, Patch, Vendor Advisory |
| Debian -- Security Information -- DSA-3388-1 ntp |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| Document Display | HPE Support Center |
CONFIRM |
support.hpe.com |
Third Party Advisory |
| Vulnerability Note VU#852879 - Network Time Protocol (NTP) Project NTP daemon (ntpd) contains multiple vulnerabilities |
CERT-VN |
www.kb.cert.org |
Third Party Advisory, US Government Resource |
| Oracle Linux Bulletin - October 2015 |
CONFIRM |
www.oracle.com |
Third Party Advisory |
| Bug 1184572 – CVE-2014-9298 ntp: drop packets with source address ::1 |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| support.ntp.org/bin/view/Main/SecurityNotice |
CONFIRM |
support.ntp.org |
Vendor Advisory |
| NTP 'ntp_io.c' Authentication Security Bypass Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 43837 HPE Comware 5 And Comware 7 Switches And Routers using NTP, Remote Denial Of Service (HPESBHF03886)