UBUNTU-CVE-2014-9295
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-9295
UBUNTU-CVE-2014-9295
Summary:
Details: Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authentication feature is used, (2) the ctl_putdata function, and (3) the configure function.
References: https://ubuntu.com/security/CVE-2014-9295, http://www.kb.cert.org/vuls/id/852879, http://cwe.mitre.org/data/definitions/121.html, http://support.ntp.org/bin/view/Main/SecurityNotice#Buffer_overflow_in_crypto_recv, https://ubuntu.com/security/notices/USN-2449-1, https://www.cve.org/CVERecord?id=CVE-2014-9295
Affected packages
Package
Name: ntp
Purl: pkg:deb/ubuntu/ntp@1:4.2.6.p5+dfsg-3ubuntu2.14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
