CVE-2009-1252
EPSS 21.1%
Description
Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.
How to fix CVE-2009-1252
To remediate CVE-2009-1252, upgrade the affected package to a fixed version below.
- Debian/ntp—upgrade to 1:4.2.4p6+dfsg-2 or later
Is CVE-2009-1252 being exploited?
Moderate — EPSS is 21.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1:4.2.4p6+dfsg-2