MEDIUM · 6.8

CVE-2014-9751

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it eas...

Vulnerability Description

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
NtpNtp>= 4.2.0, < 4.2.8
AppleMacos-
LinuxLinux Kernel-
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Workstation6.0
DebianDebian Linux7.0
OracleLinux7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-9751?

CVE-2014-9751 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it eas...

How severe is CVE-2014-9751?

CVE-2014-9751 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-9751?

Check the references section above for vendor advisories and patch information. Affected products include: Ntp Ntp, Apple Macos, Linux Linux Kernel, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server.