CVE-2009-3563 (GCVE-0-2009-3563)

Vulnerability from cvelistv5 – Published: 2009-12-09 00:00 – Updated: 2024-08-07 06:31
VLAI
Summary
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.
Severity
No CVSS data available.
CWE
  • n/a
References
URL Tags
http://www.kb.cert.org/vuls/id/568372 third-party-advisory
http://secunia.com/advisories/38832 third-party-advisory
http://kb.juniper.net/InfoCenter/index?page=conte…
https://oval.cisecurity.org/repository/search/def… vdb-entrysignature
http://support.avaya.com/css/P8/documents/100071808
http://secunia.com/advisories/38794 third-party-advisory
http://lists.vmware.com/pipermail/security-announ… mailing-list
https://www.redhat.com/archives/fedora-package-an… vendor-advisory
https://bugzilla.redhat.com/show_bug.cgi?id=531213
http://secunia.com/advisories/38764 third-party-advisory
http://support.ntp.org/bin/view/Main/SecurityNoti…
http://www.kb.cert.org/vuls/id/MAPG-7X7V6J
https://oval.cisecurity.org/repository/search/def… vdb-entrysignature
http://www.securityfocus.com/bid/37255 vdb-entry
http://marc.info/?l=bugtraq&m=136482797910018&w=2 vendor-advisory
http://secunia.com/advisories/39593 third-party-advisory
http://www-01.ibm.com/support/docview.wss?uid=isg… vendor-advisory
http://www.vupen.com/english/advisories/2010/0993 vdb-entry
http://www.debian.org/security/2009/dsa-1948 vendor-advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560074
http://aix.software.ibm.com/aix/efixes/security/x…
http://marc.info/?l=bugtraq&m=130168580504508&w=2 vendor-advisory
http://sunsolve.sun.com/search/document.do?assetk… vendor-advisory
http://www-01.ibm.com/support/docview.wss?uid=isg… vendor-advisory
https://support.ntp.org/bugs/show_bug.cgi?id=1331
https://oval.cisecurity.org/repository/search/def… vdb-entrysignature
http://secunia.com/advisories/37922 third-party-advisory
ftp://ftp.netbsd.org/pub/NetBSD/security/advisori… vendor-advisory
http://secunia.com/advisories/38834 third-party-advisory
https://www.redhat.com/archives/fedora-package-an… vendor-advisory
http://security-tracker.debian.org/tracker/CVE-20…
http://securitytracker.com/id?1023298 vdb-entry
https://oval.cisecurity.org/repository/search/def… vdb-entrysignature
https://rhn.redhat.com/errata/RHSA-2009-1651.html vendor-advisory
http://secunia.com/advisories/37629 third-party-advisory
https://rhn.redhat.com/errata/RHSA-2010-0095.html vendor-advisory
http://kb.juniper.net/InfoCenter/index?page=conte…
https://lists.ntp.org/pipermail/announce/2009-Dec… mailing-list
http://www.vupen.com/english/advisories/2010/0510 vdb-entry
https://rhn.redhat.com/errata/RHSA-2009-1648.html vendor-advisory
http://www.kb.cert.org/vuls/id/MAPG-7X7VD7
http://www.vupen.com/english/advisories/2010/0528 vdb-entry
https://www.kb.cert.org/vuls/id/417980 third-party-advisory
Date Public
2009-12-08 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-07T06:31:10.550Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": "VU#568372",
            "tags": [
              "third-party-advisory",
              "x_transferred"
            ],
            "url": "http://www.kb.cert.org/vuls/id/568372"
          },
          {
            "name": "38832",
            "tags": [
              "third-party-advisory",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/38832"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10673"
          },
          {
            "name": "oval:org.mitre.oval:def:11225",
            "tags": [
              "vdb-entry",
              "signature",
              "x_transferred"
            ],
            "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11225"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "http://support.avaya.com/css/P8/documents/100071808"
          },
          {
            "name": "38794",
            "tags": [
              "third-party-advisory",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/38794"
          },
          {
            "name": "[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates",
            "tags": [
              "mailing-list",
              "x_transferred"
            ],
            "url": "http://lists.vmware.com/pipermail/security-announce/2010/000082.html"
          },
          {
            "name": "FEDORA-2009-13121",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00809.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://bugzilla.redhat.com/show_bug.cgi?id=531213"
          },
          {
            "name": "38764",
            "tags": [
              "third-party-advisory",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/38764"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "http://support.ntp.org/bin/view/Main/SecurityNotice#DoS_attack_from_certain_NTP_mode"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "http://www.kb.cert.org/vuls/id/MAPG-7X7V6J"
          },
          {
            "name": "oval:org.mitre.oval:def:19376",
            "tags": [
              "vdb-entry",
              "signature",
              "x_transferred"
            ],
            "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19376"
          },
          {
            "name": "37255",
            "tags": [
              "vdb-entry",
              "x_transferred"
            ],
            "url": "http://www.securityfocus.com/bid/37255"
          },
          {
            "name": "SSRT101144",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "http://marc.info/?l=bugtraq\u0026m=136482797910018\u0026w=2"
          },
          {
            "name": "39593",
            "tags": [
              "third-party-advisory",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/39593"
          },
          {
            "name": "IZ71047",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "http://www-01.ibm.com/support/docview.wss?uid=isg1IZ71047"
          },
          {
            "name": "ADV-2010-0993",
            "tags": [
              "vdb-entry",
              "x_transferred"
            ],
            "url": "http://www.vupen.com/english/advisories/2010/0993"
          },
          {
            "name": "DSA-1948",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "http://www.debian.org/security/2009/dsa-1948"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560074"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "http://aix.software.ibm.com/aix/efixes/security/xntpd_advisory.asc"
          },
          {
            "name": "HPSBUX02639",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "http://marc.info/?l=bugtraq\u0026m=130168580504508\u0026w=2"
          },
          {
            "name": "1021781",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021781.1-1"
          },
          {
            "name": "IZ68659",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "http://www-01.ibm.com/support/docview.wss?uid=isg1IZ68659"
          },
          {
            "name": "SSRT100293",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "http://marc.info/?l=bugtraq\u0026m=130168580504508\u0026w=2"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://support.ntp.org/bugs/show_bug.cgi?id=1331"
          },
          {
            "name": "oval:org.mitre.oval:def:7076",
            "tags": [
              "vdb-entry",
              "signature",
              "x_transferred"
            ],
            "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7076"
          },
          {
            "name": "37922",
            "tags": [
              "third-party-advisory",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/37922"
          },
          {
            "name": "NetBSD-SA2010-005",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2010-005.txt.asc"
          },
          {
            "name": "38834",
            "tags": [
              "third-party-advisory",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/38834"
          },
          {
            "name": "FEDORA-2009-13090",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00763.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "http://security-tracker.debian.org/tracker/CVE-2009-3563"
          },
          {
            "name": "1023298",
            "tags": [
              "vdb-entry",
              "x_transferred"
            ],
            "url": "http://securitytracker.com/id?1023298"
          },
          {
            "name": "oval:org.mitre.oval:def:12141",
            "tags": [
              "vdb-entry",
              "signature",
              "x_transferred"
            ],
            "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12141"
          },
          {
            "name": "RHSA-2009:1651",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://rhn.redhat.com/errata/RHSA-2009-1651.html"
          },
          {
            "name": "37629",
            "tags": [
              "third-party-advisory",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/37629"
          },
          {
            "name": "RHSA-2010:0095",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://rhn.redhat.com/errata/RHSA-2010-0095.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10691"
          },
          {
            "name": "HPSBUX02859",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "http://marc.info/?l=bugtraq\u0026m=136482797910018\u0026w=2"
          },
          {
            "name": "[announce] 20091208 NTP 4.2.4p8 Released",
            "tags": [
              "mailing-list",
              "x_transferred"
            ],
            "url": "https://lists.ntp.org/pipermail/announce/2009-December/000086.html"
          },
          {
            "name": "ADV-2010-0510",
            "tags": [
              "vdb-entry",
              "x_transferred"
            ],
            "url": "http://www.vupen.com/english/advisories/2010/0510"
          },
          {
            "name": "RHSA-2009:1648",
            "tags": [
              "vendor-advisory",
              "x_transferred"
            ],
            "url": "https://rhn.redhat.com/errata/RHSA-2009-1648.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "http://www.kb.cert.org/vuls/id/MAPG-7X7VD7"
          },
          {
            "name": "ADV-2010-0528",
            "tags": [
              "vdb-entry",
              "x_transferred"
            ],
            "url": "http://www.vupen.com/english/advisories/2010/0528"
          },
          {
            "name": "VU#417980",
            "tags": [
              "third-party-advisory",
              "x_transferred"
            ],
            "url": "https://www.kb.cert.org/vuls/id/417980"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "n/a",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ],
      "datePublic": "2009-12-08T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "n/a",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-03-19T21:06:04.060Z",
        "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "shortName": "mitre"
      },
      "references": [
        {
          "name": "VU#568372",
          "tags": [
            "third-party-advisory"
          ],
          "url": "http://www.kb.cert.org/vuls/id/568372"
        },
        {
          "name": "38832",
          "tags": [
            "third-party-advisory"
          ],
          "url": "http://secunia.com/advisories/38832"
        },
        {
          "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10673"
        },
        {
          "name": "oval:org.mitre.oval:def:11225",
          "tags": [
            "vdb-entry",
            "signature"
          ],
          "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11225"
        },
        {
          "url": "http://support.avaya.com/css/P8/documents/100071808"
        },
        {
          "name": "38794",
          "tags": [
            "third-party-advisory"
          ],
          "url": "http://secunia.com/advisories/38794"
        },
        {
          "name": "[security-announce] 20100303 VMSA-2010-0004 ESX Service Console and vMA third party updates",
          "tags": [
            "mailing-list"
          ],
          "url": "http://lists.vmware.com/pipermail/security-announce/2010/000082.html"
        },
        {
          "name": "FEDORA-2009-13121",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00809.html"
        },
        {
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=531213"
        },
        {
          "name": "38764",
          "tags": [
            "third-party-advisory"
          ],
          "url": "http://secunia.com/advisories/38764"
        },
        {
          "url": "http://support.ntp.org/bin/view/Main/SecurityNotice#DoS_attack_from_certain_NTP_mode"
        },
        {
          "url": "http://www.kb.cert.org/vuls/id/MAPG-7X7V6J"
        },
        {
          "name": "oval:org.mitre.oval:def:19376",
          "tags": [
            "vdb-entry",
            "signature"
          ],
          "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19376"
        },
        {
          "name": "37255",
          "tags": [
            "vdb-entry"
          ],
          "url": "http://www.securityfocus.com/bid/37255"
        },
        {
          "name": "SSRT101144",
          "tags": [
            "vendor-advisory"
          ],
          "url": "http://marc.info/?l=bugtraq\u0026m=136482797910018\u0026w=2"
        },
        {
          "name": "39593",
          "tags": [
            "third-party-advisory"
          ],
          "url": "http://secunia.com/advisories/39593"
        },
        {
          "name": "IZ71047",
          "tags": [
            "vendor-advisory"
          ],
          "url": "http://www-01.ibm.com/support/docview.wss?uid=isg1IZ71047"
        },
        {
          "name": "ADV-2010-0993",
          "tags": [
            "vdb-entry"
          ],
          "url": "http://www.vupen.com/english/advisories/2010/0993"
        },
        {
          "name": "DSA-1948",
          "tags": [
            "vendor-advisory"
          ],
          "url": "http://www.debian.org/security/2009/dsa-1948"
        },
        {
          "url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560074"
        },
        {
          "url": "http://aix.software.ibm.com/aix/efixes/security/xntpd_advisory.asc"
        },
        {
          "name": "HPSBUX02639",
          "tags": [
            "vendor-advisory"
          ],
          "url": "http://marc.info/?l=bugtraq\u0026m=130168580504508\u0026w=2"
        },
        {
          "name": "1021781",
          "tags": [
            "vendor-advisory"
          ],
          "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021781.1-1"
        },
        {
          "name": "IZ68659",
          "tags": [
            "vendor-advisory"
          ],
          "url": "http://www-01.ibm.com/support/docview.wss?uid=isg1IZ68659"
        },
        {
          "name": "SSRT100293",
          "tags": [
            "vendor-advisory"
          ],
          "url": "http://marc.info/?l=bugtraq\u0026m=130168580504508\u0026w=2"
        },
        {
          "url": "https://support.ntp.org/bugs/show_bug.cgi?id=1331"
        },
        {
          "name": "oval:org.mitre.oval:def:7076",
          "tags": [
            "vdb-entry",
            "signature"
          ],
          "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7076"
        },
        {
          "name": "37922",
          "tags": [
            "third-party-advisory"
          ],
          "url": "http://secunia.com/advisories/37922"
        },
        {
          "name": "NetBSD-SA2010-005",
          "tags": [
            "vendor-advisory"
          ],
          "url": "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2010-005.txt.asc"
        },
        {
          "name": "38834",
          "tags": [
            "third-party-advisory"
          ],
          "url": "http://secunia.com/advisories/38834"
        },
        {
          "name": "FEDORA-2009-13090",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00763.html"
        },
        {
          "url": "http://security-tracker.debian.org/tracker/CVE-2009-3563"
        },
        {
          "name": "1023298",
          "tags": [
            "vdb-entry"
          ],
          "url": "http://securitytracker.com/id?1023298"
        },
        {
          "name": "oval:org.mitre.oval:def:12141",
          "tags": [
            "vdb-entry",
            "signature"
          ],
          "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12141"
        },
        {
          "name": "RHSA-2009:1651",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://rhn.redhat.com/errata/RHSA-2009-1651.html"
        },
        {
          "name": "37629",
          "tags": [
            "third-party-advisory"
          ],
          "url": "http://secunia.com/advisories/37629"
        },
        {
          "name": "RHSA-2010:0095",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://rhn.redhat.com/errata/RHSA-2010-0095.html"
        },
        {
          "url": "http://kb.juniper.net/InfoCenter/index?page=content\u0026id=JSA10691"
        },
        {
          "name": "HPSBUX02859",
          "tags": [
            "vendor-advisory"
          ],
          "url": "http://marc.info/?l=bugtraq\u0026m=136482797910018\u0026w=2"
        },
        {
          "name": "[announce] 20091208 NTP 4.2.4p8 Released",
          "tags": [
            "mailing-list"
          ],
          "url": "https://lists.ntp.org/pipermail/announce/2009-December/000086.html"
        },
        {
          "name": "ADV-2010-0510",
          "tags": [
            "vdb-entry"
          ],
          "url": "http://www.vupen.com/english/advisories/2010/0510"
        },
        {
          "name": "RHSA-2009:1648",
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://rhn.redhat.com/errata/RHSA-2009-1648.html"
        },
        {
          "url": "http://www.kb.cert.org/vuls/id/MAPG-7X7VD7"
        },
        {
          "name": "ADV-2010-0528",
          "tags": [
            "vdb-entry"
          ],
          "url": "http://www.vupen.com/english/advisories/2010/0528"
        },
        {
          "name": "VU#417980",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.kb.cert.org/vuls/id/417980"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
    "assignerShortName": "mitre",
    "cveId": "CVE-2009-3563",
    "datePublished": "2009-12-09T00:00:00.000Z",
    "dateReserved": "2009-10-05T00:00:00.000Z",
    "dateUpdated": "2024-08-07T06:31:10.550Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2009-3563",
      "date": "2026-10-03",
      "epss": "0.32059",
      "percentile": "0.98268"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Detection rules are retrieved from Rulezet.

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…