CVE-2017-6451
The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which trigger an out-of-bounds memory write.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.48% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- ntp/ntp
- Source
- cve@mitre.org
References
- http://support.ntp.org/bin/view/Main/NtpBug3378Patch, Vendor Advisory
- http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_SecuVendor Advisory
- http://www.securityfocus.com/bid/97058Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038123Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039427
- https://support.apple.com/HT208144
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us
- http://support.ntp.org/bin/view/Main/NtpBug3378Patch, Vendor Advisory
- http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_SecuVendor Advisory
- http://www.securityfocus.com/bid/97058Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038123Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039427
- https://support.apple.com/HT208144
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.