CVE-2009-1252 describes a stack-based buffer overflow in the crypto_recv function of ntpd in NTP versions before 4.2.4p7 and 4.2.5 before 4.2.5p74. This vulnerability affects systems with OpenSSL and autokey enabled, allowing remote attackers to execute arbitrary code through a crafted packet containing an extension field. The vulnerability has a CVSS score of 6.8, indicating a medium severity. It can be exploited remotely with medium attack complexity, potentially leading to partial compromise of confidentiality, integrity, and availability. Despite its age, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.4p0CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.4p0:*:*:*:*:*:*:* | ||
4.2.4p1CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.4p1:*:*:*:*:*:*:* | ||
4.2.4p2CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.4p2:*:*:*:*:*:*:* | ||
4.2.4p3CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.4p3:*:*:*:*:*:*:* | ||
4.2.4p4CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.4p4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.