VulnerabilityModified
CVE-2019-8936
NTP through 4.2.8p12 has a NULL Pointer Dereference.
HIGH 7.5EPSS 5.73%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
NTP through 4.2.8p12 has a NULL Pointer Dereference.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 5.73% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- netapp/clustered data ontap · netapp/data ontap · fedoraproject/fedora · opensuse/leap · hpe/hpux-ntp · ntp/ntp
- Source
- cve@mitre.org
References
- http://bugs.ntp.org/show_bug.cgi?id=3565Exploit, Issue Tracking, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00032.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00036.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152915/FreeBSD-Security-Advisory-FreeBSD-SA-19-04.ntp.htmlThird Party Advisory, VDB Entry
- http://support.ntp.org/bin/view/Main/SecurityNoticeRelease Notes, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NVS2CSG2TQ663CXOZZUJN4STQPMENNP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBGXY7OKWOLT6X6JAPVZRFEP4FLCGGST/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQDNHNYOJK2SRSGO23GQ2RXTOUY2HLNN/
- https://seclists.org/bugtraq/2019/May/39Issue Tracking, Mailing List, Third Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:04.ntp.ascMitigation, Third Party Advisory
- https://security.gentoo.org/glsa/201903-15Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190503-0001/Patch, Third Party Advisory
- https://support.f5.com/csp/article/K61363039Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_usThird Party Advisory
- https://usn.ubuntu.com/4563-1/
- http://bugs.ntp.org/show_bug.cgi?id=3565Exploit, Issue Tracking, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00032.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00036.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/152915/FreeBSD-Security-Advisory-FreeBSD-SA-19-04.ntp.htmlThird Party Advisory, VDB Entry
- http://support.ntp.org/bin/view/Main/SecurityNoticeRelease Notes, Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NVS2CSG2TQ663CXOZZUJN4STQPMENNP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBGXY7OKWOLT6X6JAPVZRFEP4FLCGGST/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQDNHNYOJK2SRSGO23GQ2RXTOUY2HLNN/
- https://seclists.org/bugtraq/2019/May/39Issue Tracking, Mailing List, Third Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:04.ntp.ascMitigation, Third Party Advisory
- https://security.gentoo.org/glsa/201903-15Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190503-0001/Patch, Third Party Advisory
- https://support.f5.com/csp/article/K61363039Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_usThird Party Advisory
- https://usn.ubuntu.com/4563-1/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.