Buffer overflow in ntp - CVE-2017-6459
Published: March 27, 2017 / Updated: August 8, 2020
Vulnerability identifier: #VU39360
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6459
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.
The Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via vectors related to an argument with multiple null bytes.
Affected software
ntp
Junos OS
Slackware Linux
Junos OS Evolved
Junos OS
Slackware Linux
Junos OS Evolved
How to mitigate CVE-2017-6459
Install update from vendor's website.
Junos OS - addressed in versions 12.3X48-D95, 12.3R12-S15, 14.1X53-D53, 15.1x49-D190, 15.1R7-S6, 16.1R7-S6, 16.2R3, 17.1R2-S11, 17.1R3-S1, 17.2R1-S9, 17.2R2-S8, 17.2R3-S3, 17.3R2-S5, 17.3R3-S6, 17.4R2-S7, 17.4R3, 18.1R3-S8, 18.2R2-S7, 18.2R3-S1, 18.3R1-S5, 18.3R2-S2, 18.3R3, 18.4R1-S4, 18.4R2-S1, 18.4R3, 19.1R1-S3, 19.1R2, 19.2R1-S1, 19.2R2, 19.3R1
Junos OS Evolved - update to 20.1R1-EVO
Junos OS Evolved - update to 20.1R1-EVO