VDB
CVE-2001-0414
CVE-2001-0414
PUBLISHED
KEV
CVSS 10 CRITICAL
Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.
EPSS 91.68% · 99.8th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
91.68%
99.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| dave_mills | ntpd | 4.0.99a, 4.0.99b, 4.0.99d |
| dave_mills | xntp3 | *, 5.93, 5.93c |
Timeline
- CVE Published
- Apr 4, 2001 PoC Published
- Aug 25, 2010 PoC Published
- Sep 23, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
References
- RHSA-2001:045 vendor-advisory
- 20010409 [ESA-20010409-01] xntp buffer overflow mailing-list
- SSE073 vendor-advisory
- MDKSA-2001:036 vendor-advisory
- 20010404 ntpd =< 4.0.99k remote buffer overflow mailing-list
- 2540 vdb
- FreeBSD-SA-01:31 vendor-advisory
- 805 vdb
- 20010418 IBM MSS Outside Advisory Redistribution: IBM AIX: Buffer Overflow Vulnerability in (x)ntp mailing-list
- ntpd-remote-bo(6321) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2001-0414 advisory
- https://www.debian.org/security/2001/dsa-045 url
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000392 url
- http://marc.info/?l=bugtraq&m=98654963328381&w=2 url
- http://marc.info/?l=bugtraq&m=98684532921941&w=2 url
- ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2001-004.txt.asc technical
- http://marc.info/?l=bugtraq&m=98679815917014&w=2 technical
- http://marc.info/?l=bugtraq&m=98684202610470&w=2 technical
- ftp://ftp.sco.com/SSE/sse074.ltr technical
- http://archives.neohapsis.com/archives/bugtraq/2001-04/0225.html technical
…and 5 more