Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.104669
Category:General
Title:NTP <= 4.2.8p15 Multiple Vulnerabilities
Summary:NTP is prone to multiple vulnerabilities.
Description:Summary:
NTP is prone to multiple vulnerabilities.

Vulnerability Insight:
The following flaws exist:

- CVE-2023-26551: mstolfp in libntp/mstolfp.c has an out-of-bounds write in the cp loop. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.

- CVE-2023-26552: mstolfp in libntp/mstolfp.c has an out-of-bounds write when adding a decimal
point. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.

- CVE-2023-26553: mstolfp in libntp/mstolfp.c has an out-of-bounds write when copying the trailing
number. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.

- CVE-2023-26554: mstolfp in libntp/mstolfp.c has an out-of-bounds write when adding a '\0'
character. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.

- CVE-2023-26555: praecis_parse in ntpd/refclock_palisade.c has an out-of-bounds write. Any attack
method would be complex, e.g., with a manipulated GPS receiver.

Affected Software/OS:
NTPd version 4.2.8p15 and prior.

Solution:
Update to version 4.2.8p16 or later.

CVSS Score:
6.2

CVSS Vector:
AV:L/AC:H/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-26551
https://github.com/spwpun/ntp-4.2.8p15-cves/blob/main/CVE-2023-26551
https://github.com/spwpun/ntp-4.2.8p15-cves/issues/1#issuecomment-1506667321
Common Vulnerability Exposure (CVE) ID: CVE-2023-26552
https://github.com/spwpun/ntp-4.2.8p15-cves/blob/main/CVE-2023-26552
Common Vulnerability Exposure (CVE) ID: CVE-2023-26553
https://github.com/spwpun/ntp-4.2.8p15-cves/blob/main/CVE-2023-26553
Common Vulnerability Exposure (CVE) ID: CVE-2023-26554
https://github.com/spwpun/ntp-4.2.8p15-cves/blob/main/CVE-2023-26554
Common Vulnerability Exposure (CVE) ID: CVE-2023-26555
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IY2SVYH4MKPAXEYHCCXD3Z6VGINLSVHK/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y3VHEHHWCTYSB7HVJLYPVK4RPJZ5LX52/
https://github.com/spwpun/ntp-4.2.8p15-cves/blob/main/CVE-2023-26555
https://github.com/spwpun/ntp-4.2.8p15-cves/issues/1#issuecomment-1506546409
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.