ntpd: DoS with mode 7 packets (VU#568372)
Published Dec 9, 2009
6.4
MEDIUMCVSS 2.0
EPSS 32.06%
Description
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.
Affected products
No data.
- ≤ 4.2.2p4
- 4.0.72
- 4.0.73
- 4.0.90
- 4.0.91
- 4.0.92
- 4.0.93
- 4.0.94
- 4.0.95
- 4.0.96
- 4.0.97
- 4.0.98
- 4.0.99
- 4.1.0
- 4.1.2
- 4.2.0
- 4.2.2
- 4.2.2p1
- 4.2.2p2
- 4.2.2p3
- 4.2.5
No data.
Red Hat Enterprise Linux 3
ntp-0:4.1.2-6.el3
Fixed · RHSA-2009:1651
Red Hat Enterprise Linux 4
ntp-0:4.2.0.a.20040617-8.el4_8.1
Fixed · RHSA-2009:1648
Red Hat Enterprise Linux 5
ntp-0:4.2.2p1-9.el5_4.1
Fixed · RHSA-2009:1648
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | ntp-0:4.1.2-6.el3 | Fixed | RHSA-2009:1651 |
| Red Hat Enterprise Linux 4 | ntp-0:4.2.0.a.20040617-8.el4_8.1 | Fixed | RHSA-2009:1648 |
| Red Hat Enterprise Linux 5 | ntp-0:4.2.2p1-9.el5_4.1 | Fixed | RHSA-2009:1648 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 32.06% (0.32059) | 98.26th | v5 (v2026.06.15) |
| Jun 15, 2026 | 32.29% (0.32288) | 98.09th | v5 (v2026.06.15) |
| May 1, 2026 | 81.11% (0.81107) | 99.16th | v4 (v2025.03.14) |
| Mar 21, 2026 | 79.91% (0.79907) | 99.09th | v4 (v2025.03.14) |
| Feb 26, 2026 | 81.09% (0.81088) | 99.13th | v4 (v2025.03.14) |
| Dec 21, 2025 | 82.43% (0.82429) | 99.19th | v4 (v2025.03.14) |
| Aug 10, 2025 | 86.93% (0.86927) | 99.39th | v4 (v2025.03.14) |
| Jun 6, 2025 | 85.12% (0.85119) | 99.29th | v4 (v2025.03.14) |
| May 5, 2025 | 83.12% (0.83121) | 99.19th | v4 (v2025.03.14) |
| May 3, 2025 | 87.70% (0.87697) | 99.43th | v4 (v2025.03.14) |
| Apr 28, 2025 | 86.34% (0.86339) | 99.34th | v4 (v2025.03.14) |
| Apr 27, 2025 | 79.62% (0.79616) | 99.01th | v4 (v2025.03.14) |
| Mar 30, 2025 | 64.95% (0.64951) | 98.34th | v4 (v2025.03.14) |
| Mar 29, 2025 | 67.22% (0.67215) | 98.02th | v4 (v2025.03.14) |
| Mar 17, 2025 | 64.95% (0.64951) | 98.32th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.52% (0.96520) | 99.66th | v3 (v2023.03.01) |
| Jun 8, 2024 | 96.49% (0.96493) | 99.59th | v3 (v2023.03.01) |
| Mar 13, 2024 | 96.31% (0.96315) | 99.50th | v3 (v2023.03.01) |
| Sep 14, 2023 | 96.56% (0.96565) | 99.45th | v3 (v2023.03.01) |
| Aug 2, 2023 | 96.69% (0.96694) | 99.47th | v3 (v2023.03.01) |
| Mar 7, 2023 | 96.78% (0.96776) | 99.40th | v3 (v2023.03.01) |
| Mar 6, 2023 | 55.63% (0.55631) | 98.82th | v2 (v2022.01.01) |
| Feb 4, 2022 | 55.63% (0.55631) | 98.47th | v2 (v2022.01.01) |
No CWE recorded.
References (46)
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2010-005.txt.asc vendor-advisory
- http://aix.software.ibm.com/aix/efixes/security/xntpd_advisory.asc
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560074
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691
- http://lists.vmware.com/pipermail/security-announce/2010/000082.html mailing-list
- http://marc.info/?l=bugtraq&m=130168580504508&w=2 vendor-advisory
- http://marc.info/?l=bugtraq&m=136482797910018&w=2 vendor-advisory
- http://secunia.com/advisories/37629 third-party-advisory
- http://secunia.com/advisories/37922 third-party-advisory
- http://secunia.com/advisories/38764 third-party-advisory
- http://secunia.com/advisories/38794 third-party-advisory
- http://secunia.com/advisories/38832 third-party-advisory
- http://secunia.com/advisories/38834 third-party-advisory
- http://secunia.com/advisories/39593 third-party-advisory
- http://security-tracker.debian.org/tracker/CVE-2009-3563
- http://securitytracker.com/id?1023298 vdb-entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021781.1-1 vendor-advisory
- http://support.avaya.com/css/P8/documents/100071808
- http://support.ntp.org/bin/view/Main/SecurityNotice#DoS_attack_from_certain_NTP_mode Patch
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ68659 vendor-advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ71047 vendor-advisory
- http://www.debian.org/security/2009/dsa-1948 vendor-advisoryPatch
- http://www.kb.cert.org/vuls/id/568372 third-party-advisoryPatchUS Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-7X7V6J
- http://www.kb.cert.org/vuls/id/MAPG-7X7VD7
- http://www.securityfocus.com/bid/37255 vdb-entryPatch
- http://www.vupen.com/english/advisories/2010/0510 vdb-entry
- http://www.vupen.com/english/advisories/2010/0528 vdb-entry
- http://www.vupen.com/english/advisories/2010/0993 vdb-entry
- https://access.redhat.com/security/cve/CVE-2009-3563 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=531213 Issue Tracking
- https://lists.ntp.org/pipermail/announce/2009-December/000086.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2009-3563
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11225 vdb-entrysignature
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12141 vdb-entrysignature
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19376 vdb-entrysignature
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7076 vdb-entrysignature
- https://rhn.redhat.com/errata/RHSA-2009-1648.html vendor-advisory
- https://rhn.redhat.com/errata/RHSA-2009-1651.html vendor-advisory
- https://rhn.redhat.com/errata/RHSA-2010-0095.html vendor-advisory
- https://support.ntp.org/bugs/show_bug.cgi?id=1331
- https://www.cve.org/CVERecord?id=CVE-2009-3563
- https://www.kb.cert.org/vuls/id/417980 third-party-advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00763.html vendor-advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00809.html vendor-advisory
Change history (0)
No recorded changes yet.