CVE-2017-6458: Buffer Overflow
Last updated 24 July 2024
Other sources
Multiple buffer overflows in the ctlput functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
— Launchpad
ntp. Multiple issues were addressed by updating to version 4.2.8p10
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ntpto a version that resolves this vulnerability.Fixed in 1:4.2.8p15+dfsg-1 - Upgrade
Upgrade
macOS High Sierrato a version that resolves this vulnerability.Fixed in 10.13 - Upgrade
Upgrade
ntpto a version that resolves this vulnerability.Fixed in 4.2.8p10 - Upgrade
Upgrade
ntpto a version that resolves this vulnerability.Fixed in 4.3.94
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-13832
- CVE-2016-0736
- CVE-2016-2161
- CVE-2016-5387
- CVE-2016-8740
- CVE-2016-8743
- CVE-2017-13909
- CVE-2017-13809
- CVE-2017-7084
- CVE-2017-7074
- CVE-2017-13820
- CVE-2017-13807
- CVE-2017-7143
- CVE-2017-13829
- CVE-2017-13833
- CVE-2017-7083
- CVE-2017-13821
- CVE-2017-0381
- CVE-2017-13825
- CVE-2017-13890
- CVE-2017-13851
- CVE-2017-7138
- CVE-2017-7121
- CVE-2017-7122
- CVE-2017-7123
- CVE-2017-7124
- CVE-2017-7125
- CVE-2017-7126
- CVE-2017-13815
- CVE-2017-13828
- CVE-2017-13811
- CVE-2017-13835
- CVE-2017-11103
- CVE-2017-13819
- CVE-2017-13830
- CVE-2017-13814
- CVE-2017-13831
- CVE-2017-13837
- CVE-2017-13906
- CVE-2017-7077
- CVE-2017-7119
- CVE-2017-7114
- CVE-2017-13810
- CVE-2017-13817
- CVE-2017-13818
- CVE-2017-13836
- CVE-2017-13841
- CVE-2017-13840
- CVE-2017-13842
- CVE-2017-13782
- CVE-2017-13843
- CVE-2017-13854
- CVE-2017-13834
- CVE-2017-13873
- CVE-2017-13827
- CVE-2017-13813
- CVE-2017-13816
- CVE-2017-13812
- CVE-2016-4736
- CVE-2017-7086
- CVE-2017-1000373
- CVE-2016-9063
- CVE-2017-9233
- CVE-2018-4302
- CVE-2017-5130
- CVE-2017-7376
- CVE-2017-9050
- CVE-2017-9049
- CVE-2017-7141
- CVE-2017-7078
- CVE-2017-6451
- CVE-2017-6452
- CVE-2017-6455
- CVE-2017-6458
- CVE-2017-6459
- CVE-2017-6460
- CVE-2017-6462
- CVE-2017-6463
- CVE-2017-6464
- CVE-2016-9042
- CVE-2017-13824
- CVE-2017-13846
- CVE-2017-10140
- CVE-2017-13822
- CVE-2017-7132
- CVE-2017-13823
- CVE-2017-13808
- CVE-2017-13838
- CVE-2017-7082
- CVE-2017-7080
- CVE-2017-13908
- CVE-2017-13839
- CVE-2017-13910
- CVE-2017-10989
- CVE-2017-7128
- CVE-2017-7129
- CVE-2017-7130
- CVE-2017-7127
- CVE-2016-9840
- CVE-2016-9841
- CVE-2016-9842
- CVE-2016-9843
Frequently Asked Questions
What is CVE-2017-6458?
CVE-2017-6458 is a vulnerability in NTP that allows remote authenticated users to have unspecified impact via a long variable.
What is the severity of CVE-2017-6458?
CVE-2017-6458 has a severity rating of 8.8 (high).
How can I fix CVE-2017-6458?
To fix CVE-2017-6458, update NTP to version 4.2.8p10 or later.
Where can I find more information about CVE-2017-6458?
You can find more information about CVE-2017-6458 at the following references: [http://support.ntp.org/bin/view/Main/NtpBug3379](http://support.ntp.org/bin/view/Main/NtpBug3379), [http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secu](http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secu), [http://www.securitytracker.com/id/1038123](http://www.securitytracker.com/id/1038123).
What is the Common Weakness Enumeration (CWE) for CVE-2017-6458?
The CWE for CVE-2017-6458 is CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer).