Ntpd Remote Buffer Overflow Vulnerability

BID:2540

Info

Ntpd Remote Buffer Overflow Vulnerability

Bugtraq ID: 2540
Class: Boundary Condition Error
CVE: CVE-2001-0414
Remote: Yes
Local: No
Published: Apr 04 2001 12:00AM
Updated: Nov 05 2007 05:05PM
Credit: This vulnerability was published in an exploit written by Przemyslaw Frasunek <[email protected]> and posted to Bugtraq on April 4, 2001.
Vulnerable: Sun Solaris 8_x86
Sun Solaris 8_sparc
Sun Solaris 7.0_x86
Sun Solaris 7.0
Sun Solaris 2.6_x86
Sun Solaris 2.6
HP HP-UX (VVOS) 11.0.4
HP HP-UX (VVOS) 10.24
HP HP-UX 11.11
HP HP-UX 11.0
HP HP-UX 10.20
HP HP-UX 10.10
HP HP-UX 10.0 1
Dave Mills xntp3 5.93 e
Dave Mills xntp3 5.93 d
Dave Mills xntp3 5.93 c
Dave Mills xntp3 5.93 b
Dave Mills xntp3 5.93 a
Dave Mills xntp3 5.93
Dave Mills ntpd 4.0.99 k
+ MandrakeSoft Corporate Server 1.0.1
+ Mandriva Linux Mandrake 7.2
+ Mandriva Linux Mandrake 7.1
- Slackware Linux 7.0
Dave Mills ntpd 4.0.99 j
Dave Mills ntpd 4.0.99 i
Dave Mills ntpd 4.0.99 h
Dave Mills ntpd 4.0.99 g
+ Debian Linux 2.2
Dave Mills ntpd 4.0.99 f
Dave Mills ntpd 4.0.99 e
Dave Mills ntpd 4.0.99 d
Dave Mills ntpd 4.0.99 c
Dave Mills ntpd 4.0.99 b
+ FreeBSD FreeBSD 4.2 -RELEASE
Dave Mills ntpd 4.0.99 a
Dave Mills ntpd 4.0.99
Cisco Voice Services Provisioning Tool
+ Sun Solaris 2.6
Cisco Virtual Switch Controller 3000
Cisco SC2200
Cisco PGW2200 PSTN Gateway
+ Sun Solaris 2.6
Cisco IP Manager 2.0
Cisco IP Manager 1.0
Cisco IOS 12.2YC
Cisco IOS 12.2YA
Cisco IOS 12.2XQ
Cisco IOS 12.2XQ
Cisco IOS 12.2XH
Cisco IOS 12.2XE
Cisco IOS 12.2XD
Cisco IOS 12.2XB
Cisco IOS 12.2XA
Cisco IOS 12.2T
Cisco IOS 12.2S
Cisco IOS 12.2PI
Cisco IOS 12.2PB
Cisco IOS 12.2DA
Cisco IOS 12.2BX
Cisco IOS 12.2BW
Cisco IOS 12.2B
Cisco IOS 12.2
Cisco IOS 12.1YF
Cisco IOS 12.1YD
Cisco IOS 12.1YC
Cisco IOS 12.1YB
Cisco IOS 12.1YA
Cisco IOS 12.1XZ
Cisco IOS 12.1XY
Cisco IOS 12.1XX
Cisco IOS 12.1XW
Cisco IOS 12.1XV
Cisco IOS 12.1XU
Cisco IOS 12.1XT
Cisco IOS 12.1XS
Cisco IOS 12.1XR
Cisco IOS 12.1XQ
Cisco IOS 12.1XP
Cisco IOS 12.1XM
Cisco IOS 12.1XL
Cisco IOS 12.1XK
Cisco IOS 12.1XJ
Cisco IOS 12.1XI
Cisco IOS 12.1XH
Cisco IOS 12.1XG
Cisco IOS 12.1XF
Cisco IOS 12.1XE
Cisco IOS 12.1XD
Cisco IOS 12.1XC
Cisco IOS 12.1XB
Cisco IOS 12.1XA
Cisco IOS 12.1T
Cisco IOS 12.1EZ
Cisco IOS 12.1EY
Cisco IOS 12.1EX
Cisco IOS 12.1EC
Cisco IOS 12.1E
Cisco IOS 12.1DC
Cisco IOS 12.1DB
Cisco IOS 12.1DA
Cisco IOS 12.1CX
Cisco IOS 12.1AA
Cisco IOS 12.1
Cisco IOS 12.0XV
Cisco IOS 12.0XU
Cisco IOS 12.0XS
Cisco IOS 12.0XR
Cisco IOS 12.0XQ
Cisco IOS 12.0XP
Cisco IOS 12.0XN
Cisco IOS 12.0XM
Cisco IOS 12.0XL
Cisco IOS 12.0XJ
Cisco IOS 12.0XI
Cisco IOS 12.0XH
Cisco IOS 12.0XG
Cisco IOS 12.0XF
Cisco IOS 12.0XE
Cisco IOS 12.0XD
Cisco IOS 12.0XC
Cisco IOS 12.0XB
Cisco IOS 12.0XA
Cisco IOS 12.0WT
Cisco IOS 12.0WC
Cisco IOS 12.0T
Cisco IOS 12.0ST
Cisco IOS 12.0SL
Cisco IOS 12.0SC
Cisco IOS 12.0S
Cisco IOS 12.0DC
Cisco IOS 12.0DB
Cisco IOS 12.0DA
Cisco IOS 12.0(7)XK
Cisco IOS 12.0(5)XK
Cisco IOS 12.0(14)W5(20)
Cisco IOS 12.0(13)W5(19c)
Cisco IOS 12.0(10)W5(18g)
Cisco IOS 12.0
Cisco IOS 11.3XA
Cisco IOS 11.3WA4
Cisco IOS 11.3T
Cisco IOS 11.3NA
Cisco IOS 11.3MA
Cisco IOS 11.3HA
Cisco IOS 11.3DB
Cisco IOS 11.3DA
Cisco IOS 11.3AA
Cisco IOS 11.3
Cisco IOS 11.2XA
Cisco IOS 11.2WA4
Cisco IOS 11.2SA
Cisco IOS 11.2P
Cisco IOS 11.2GS
Cisco IOS 11.2F
Cisco IOS 11.2BC
Cisco IOS 11.2
Cisco IOS 11.1IA
Cisco IOS 11.1CT
Cisco IOS 11.1CC
Cisco IOS 11.1CA
Cisco IOS 11.1AA
Cisco IOS 11.1
Cisco IOS 11.0
Cisco IOS 10.3
Cisco BTS 10200
Cisco Billing and Management Server
+ Sun Solaris 2.6
Apple Mac OS X 10.0.1
Apple Mac OS X 10.0
Not Vulnerable: Cisco IOS 12.2DD
Cisco IOS 12.2(4)T
Cisco IOS 12.2(4)
Cisco IOS 12.2(3.4)BP
Cisco IOS 12.2(3)
Cisco IOS 12.2(2)XA1
Cisco IOS 12.2(2)XA
Cisco IOS 12.2(2)B
Cisco IOS 12.2(1b)
Cisco IOS 12.2(1.4)S
Cisco IOS 12.2(1.1)PI
Cisco IOS 12.2(1)XQ
Cisco IOS 12.2(1)XH
Cisco IOS 12.2(1)XE
Cisco IOS 12.2(1)XD1
Cisco IOS 12.1(9)AA
Cisco IOS 12.1(9)
Cisco IOS 12.1(8a)E
Cisco IOS 12.1(7)EC
Cisco IOS 12.1(7)CX
Cisco IOS 12.1(6)EZ2
Cisco IOS 12.1(6)EY
Cisco IOS 12.1(5)YF2
Cisco IOS 12.1(5)YD2
Cisco IOS 12.1(5)YC1
Cisco IOS 12.1(5)YB4
Cisco IOS 12.1(5)XV3
Cisco IOS 12.1(5)XS2
Cisco IOS 12.1(5)XM4
Cisco IOS 12.1(5)T9
Cisco IOS 12.1(2)XF4
Cisco IOS 12.0WC
Cisco IOS 12.0(5)YB4
Cisco IOS 12.0(5)WC2
Cisco IOS 12.0(17)ST1
Cisco IOS 12.0(17)SL2
Apple Mac OS X 10.0.2

Discussion

Ntpd Remote Buffer Overflow Vulnerability

NTP, the Network Time Protocol, is used to synchronize the time between a computer and another system or time reference. It uses UDP as a transport protocol. There are two protocol versions in use: NTP v3 and NTP v4. The 'ntpd' daemon implementing version 3 is called 'xntp3'; the version implementing version 4 is called 'ntp'.

On UNIX systems, the 'ntpd' daemon is available to regularly synchronize system time with internet time servers.

Many versions of 'ntpd' are prone to a remotely exploitable buffer-overflow issue. A remote attacker may be able to crash the daemon or execute arbitrary code on the host.

If successful, the attacker may gain root access on the victim host or may denial NTP service on the affected host.

Exploit / POC

Ntpd Remote Buffer Overflow Vulnerability

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

Przemyslaw Frasunek <[email protected]> has written an exploit for this vulnerability.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report