Ntpd Remote Buffer Overflow Vulnerability
BID:2540
Info
Ntpd Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 2540 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0414 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2001 12:00AM |
| Updated: | Nov 05 2007 05:05PM |
| Credit: | This vulnerability was published in an exploit written by Przemyslaw Frasunek <[email protected]> and posted to Bugtraq on April 4, 2001. |
| Vulnerable: |
Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 7.0_x86 Sun Solaris 7.0 Sun Solaris 2.6_x86 Sun Solaris 2.6 HP HP-UX (VVOS) 11.0.4 HP HP-UX (VVOS) 10.24 HP HP-UX 11.11 HP HP-UX 11.0 HP HP-UX 10.20 HP HP-UX 10.10 HP HP-UX 10.0 1 Dave Mills xntp3 5.93 e Dave Mills xntp3 5.93 d Dave Mills xntp3 5.93 c Dave Mills xntp3 5.93 b Dave Mills xntp3 5.93 a Dave Mills xntp3 5.93 Dave Mills ntpd 4.0.99 k Dave Mills ntpd 4.0.99 j Dave Mills ntpd 4.0.99 i Dave Mills ntpd 4.0.99 h Dave Mills ntpd 4.0.99 g Dave Mills ntpd 4.0.99 f Dave Mills ntpd 4.0.99 e Dave Mills ntpd 4.0.99 d Dave Mills ntpd 4.0.99 c Dave Mills ntpd 4.0.99 b Dave Mills ntpd 4.0.99 a Dave Mills ntpd 4.0.99 Cisco Voice Services Provisioning Tool Cisco Virtual Switch Controller 3000 Cisco SC2200 Cisco PGW2200 PSTN Gateway Cisco IP Manager 2.0 Cisco IP Manager 1.0 Cisco IOS 12.2YC Cisco IOS 12.2YA Cisco IOS 12.2XQ Cisco IOS 12.2XQ Cisco IOS 12.2XH Cisco IOS 12.2XE Cisco IOS 12.2XD Cisco IOS 12.2XB Cisco IOS 12.2XA Cisco IOS 12.2T Cisco IOS 12.2S Cisco IOS 12.2PI Cisco IOS 12.2PB Cisco IOS 12.2DA Cisco IOS 12.2BX Cisco IOS 12.2BW Cisco IOS 12.2B Cisco IOS 12.2 Cisco IOS 12.1YF Cisco IOS 12.1YD Cisco IOS 12.1YC Cisco IOS 12.1YB Cisco IOS 12.1YA Cisco IOS 12.1XZ Cisco IOS 12.1XY Cisco IOS 12.1XX Cisco IOS 12.1XW Cisco IOS 12.1XV Cisco IOS 12.1XU Cisco IOS 12.1XT Cisco IOS 12.1XS Cisco IOS 12.1XR Cisco IOS 12.1XQ Cisco IOS 12.1XP Cisco IOS 12.1XM Cisco IOS 12.1XL Cisco IOS 12.1XK Cisco IOS 12.1XJ Cisco IOS 12.1XI Cisco IOS 12.1XH Cisco IOS 12.1XG Cisco IOS 12.1XF Cisco IOS 12.1XE Cisco IOS 12.1XD Cisco IOS 12.1XC Cisco IOS 12.1XB Cisco IOS 12.1XA Cisco IOS 12.1T Cisco IOS 12.1EZ Cisco IOS 12.1EY Cisco IOS 12.1EX Cisco IOS 12.1EC Cisco IOS 12.1E Cisco IOS 12.1DC Cisco IOS 12.1DB Cisco IOS 12.1DA Cisco IOS 12.1CX Cisco IOS 12.1AA Cisco IOS 12.1 Cisco IOS 12.0XV Cisco IOS 12.0XU Cisco IOS 12.0XS Cisco IOS 12.0XR Cisco IOS 12.0XQ Cisco IOS 12.0XP Cisco IOS 12.0XN Cisco IOS 12.0XM Cisco IOS 12.0XL Cisco IOS 12.0XJ Cisco IOS 12.0XI Cisco IOS 12.0XH Cisco IOS 12.0XG Cisco IOS 12.0XF Cisco IOS 12.0XE Cisco IOS 12.0XD Cisco IOS 12.0XC Cisco IOS 12.0XB Cisco IOS 12.0XA Cisco IOS 12.0WT Cisco IOS 12.0WC Cisco IOS 12.0T Cisco IOS 12.0ST Cisco IOS 12.0SL Cisco IOS 12.0SC Cisco IOS 12.0S Cisco IOS 12.0DC Cisco IOS 12.0DB Cisco IOS 12.0DA Cisco IOS 12.0(7)XK Cisco IOS 12.0(5)XK Cisco IOS 12.0(14)W5(20) Cisco IOS 12.0(13)W5(19c) Cisco IOS 12.0(10)W5(18g) Cisco IOS 12.0 Cisco IOS 11.3XA Cisco IOS 11.3WA4 Cisco IOS 11.3T Cisco IOS 11.3NA Cisco IOS 11.3MA Cisco IOS 11.3HA Cisco IOS 11.3DB Cisco IOS 11.3DA Cisco IOS 11.3AA Cisco IOS 11.3 Cisco IOS 11.2XA Cisco IOS 11.2WA4 Cisco IOS 11.2SA Cisco IOS 11.2P Cisco IOS 11.2GS Cisco IOS 11.2F Cisco IOS 11.2BC Cisco IOS 11.2 Cisco IOS 11.1IA Cisco IOS 11.1CT Cisco IOS 11.1CC Cisco IOS 11.1CA Cisco IOS 11.1AA Cisco IOS 11.1 Cisco IOS 11.0 Cisco IOS 10.3 Cisco BTS 10200 Cisco Billing and Management Server Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 |
| Not Vulnerable: |
Cisco IOS 12.2DD Cisco IOS 12.2(4)T Cisco IOS 12.2(4) Cisco IOS 12.2(3.4)BP Cisco IOS 12.2(3) Cisco IOS 12.2(2)XA1 Cisco IOS 12.2(2)XA Cisco IOS 12.2(2)B Cisco IOS 12.2(1b) Cisco IOS 12.2(1.4)S Cisco IOS 12.2(1.1)PI Cisco IOS 12.2(1)XQ Cisco IOS 12.2(1)XH Cisco IOS 12.2(1)XE Cisco IOS 12.2(1)XD1 Cisco IOS 12.1(9)AA Cisco IOS 12.1(9) Cisco IOS 12.1(8a)E Cisco IOS 12.1(7)EC Cisco IOS 12.1(7)CX Cisco IOS 12.1(6)EZ2 Cisco IOS 12.1(6)EY Cisco IOS 12.1(5)YF2 Cisco IOS 12.1(5)YD2 Cisco IOS 12.1(5)YC1 Cisco IOS 12.1(5)YB4 Cisco IOS 12.1(5)XV3 Cisco IOS 12.1(5)XS2 Cisco IOS 12.1(5)XM4 Cisco IOS 12.1(5)T9 Cisco IOS 12.1(2)XF4 Cisco IOS 12.0WC Cisco IOS 12.0(5)YB4 Cisco IOS 12.0(5)WC2 Cisco IOS 12.0(17)ST1 Cisco IOS 12.0(17)SL2 Apple Mac OS X 10.0.2 |
Discussion
Ntpd Remote Buffer Overflow Vulnerability
NTP, the Network Time Protocol, is used to synchronize the time between a computer and another system or time reference. It uses UDP as a transport protocol. There are two protocol versions in use: NTP v3 and NTP v4. The 'ntpd' daemon implementing version 3 is called 'xntp3'; the version implementing version 4 is called 'ntp'.
On UNIX systems, the 'ntpd' daemon is available to regularly synchronize system time with internet time servers.
Many versions of 'ntpd' are prone to a remotely exploitable buffer-overflow issue. A remote attacker may be able to crash the daemon or execute arbitrary code on the host.
If successful, the attacker may gain root access on the victim host or may denial NTP service on the affected host.
NTP, the Network Time Protocol, is used to synchronize the time between a computer and another system or time reference. It uses UDP as a transport protocol. There are two protocol versions in use: NTP v3 and NTP v4. The 'ntpd' daemon implementing version 3 is called 'xntp3'; the version implementing version 4 is called 'ntp'.
On UNIX systems, the 'ntpd' daemon is available to regularly synchronize system time with internet time servers.
Many versions of 'ntpd' are prone to a remotely exploitable buffer-overflow issue. A remote attacker may be able to crash the daemon or execute arbitrary code on the host.
If successful, the attacker may gain root access on the victim host or may denial NTP service on the affected host.
Exploit / POC
Ntpd Remote Buffer Overflow Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Przemyslaw Frasunek <[email protected]> has written an exploit for this vulnerability.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Przemyslaw Frasunek <[email protected]> has written an exploit for this vulnerability.