Vulnerability Note VU#970472
Network Time Protocol ([x]ntpd) daemon contains buffer overflow in ntp_control:ctl_getitem() function
Overview
There is a buffer overflow defect in the ctl_getitem() function of the Network Time Protocol (NTP) daemon responsible for providing accurate time reports used for synchronizing the clocks on installed systems. All NTP daemons based on code maintained at the University of Delaware since NTPv2 are assumed at risk.
Description
The buffer overflow condition appears in the ctl_getitem() function in ntp_control.c, the NTP control code. Because the ntp protocol uses UDP, attacks attempting to exploit this vulnerability will likely be spoofed. |
Impact
It has been reported that a remote intruder can execute arbitrary code with the default privileges on the running daemon, typically root. While this report is still being evaluated, crashing of the NTP daemon has been confirmed. |
Solution
Apply patches supplied by your vendor |
Until patches can be applied, the CERT/CC strongly urges affected sites to block ntp requests (123/{tcp,udp}) at their network perimeter or disable ntpd altogether. It is unclear at this time if using secured NTP services provides a full defense against all attacks attempting to exploit this vulnerability. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Berkeley Software Design, Inc. | Affected | - | 10 Apr 2001 |
| Compaq Computer Corporation | Affected | 05 Apr 2001 | 03 May 2001 |
| Debian Linux | Affected | - | 10 Apr 2001 |
| FreeBSD, Inc. | Affected | 05 Apr 2001 | 13 Apr 2001 |
| Hewlett-Packard Company | Affected | - | 09 Apr 2001 |
| IBM Corporation | Affected | 05 Apr 2001 | 21 May 2008 |
| Mandriva, Inc. | Affected | - | 06 Apr 2001 |
| NetBSD | Affected | 05 Apr 2001 | 05 Apr 2001 |
| OpenBSD | Affected | 05 Apr 2001 | 06 Apr 2001 |
| Red Hat, Inc. | Affected | 05 Apr 2001 | 09 Apr 2001 |
| Slackware | Affected | - | 09 Apr 2001 |
| Sun Microsystems, Inc. | Affected | 05 Apr 2001 | 31 Oct 2001 |
| SUSE Linux | Affected | - | 16 Apr 2001 |
| The SCO Group (SCO Linux) | Affected | 05 Apr 2001 | 09 Apr 2001 |
| The SCO Group (SCO Unix) | Affected | - | 16 Apr 2001 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- https://www.kb.cert.org/vuls/970472
- ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2001-004.txt.asc
- http://www.freebsd.org/cgi/cvsweb.cgi/src/contrib/ntp/ntpd/ntp_control.c?r1+=1.1&r2=1.2
- http://www.FreeBSD.org/cgi/cvsweb.cgi/ports/net/ntp/files/patch-ntp_control.c (patch for ntp-4.0.99k)
- http://www.faqs.org/rfcs/rfc1305.html
- http://www.ntp.org/
- http://www.securityfocus.com/bid/2540
- http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?type=0&doc=secbull%2F211&display=plain
Credit
The CERT/CC thanks Przemyslaw Frasunek for reporting this issue.
This document was written by Jeffrey S. Havrilla
Other Information
- CVE IDs: CVE-2001-0414
- Date Public: 04 Apr 2001
- Date First Published: 05 Apr 2001
- Date Last Updated: 22 May 2008
- Severity Metric: 79.65
- Document Revision: 35
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.