CVE-2014-9295
EPSS 78.1%
描述
Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authentication feature is used, (2) the ctl_putdata function, and (3) the configure function.
如何修補 CVE-2014-9295
要修補 CVE-2014-9295,請將受影響套件升級到下列已修補版本。
- Debian/ntp—升級至 1:4.2.6.p5+dfsg-3.2 或更新版本
CVE-2014-9295 正在被利用嗎?
可能 — EPSS 為 78.1%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 1:4.2.6.p5+dfsg-3.2