CVE-2014-9295 describes multiple stack-based buffer overflows in NTP versions prior to 4.2.8, specifically within the ntpd daemon. These flaws, found in functions like crypto_recv, ctl_putdata, and configure, allow unauthenticated remote attackers to execute arbitrary code on affected systems. With a CVSS score of 7.5, this vulnerability is considered highly severe due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the KEV catalog or public exploit frameworks like Metasploit or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating its perceived risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.7CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.