ntp: Potential Overflows in ctl_put() functions
Published Mar 27, 2017
8.8
HIGHCVSS 3.1
EPSS 6.51%
Description
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.
Affected products
No data.
Configuration 1
- < 4.2.8
- ≥ 4.3.0 · < 4.3.94
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
- 4.2.8
Configuration 2
- < c.4.2.8.4.0
Configuration 4
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 5
ntp
Not affected
Red Hat Enterprise Linux 6
ntp
Not affected
Red Hat Enterprise Linux 7
ntp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | ntp | Not affected | n/a |
| Red Hat Enterprise Linux 6 | ntp | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ntp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The security assessment from cure53 clarifies that this issue (identified as NTP-01-0004) is not a vulnerability per se, but a weakness in ntp's internal coding style that may cause a vulnerability if particularly long variable names are defined at compile time. No such variable names are defined in upstream source code, nor in Fedora or Red Hat Enterprise Linux versions of ntp.
Red Hat mitigation
Implement BCP-38. If you don't want to upgrade, then don't setvar variable names longer than 200-512 bytes in your ntp.conf file. Properly monitor your ntpd instances, and auto-restart ntpd (without -g) if it stops running.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (26 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.51% (0.06515) | 93.57th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.51% (0.06515) | 92.88th | v5 (v2026.06.15) |
| May 23, 2026 | 8.53% (0.08526) | 92.48th | v4 (v2025.03.14) |
| May 4, 2026 | 10.61% (0.10612) | 93.32th | v4 (v2025.03.14) |
| May 3, 2026 | 7.43% (0.07427) | 91.78th | v4 (v2025.03.14) |
| Jan 18, 2026 | 9.35% (0.09351) | 92.52th | v4 (v2025.03.14) |
| Dec 28, 2025 | 12.06% (0.12057) | 93.55th | v4 (v2025.03.14) |
| Dec 27, 2025 | 5.22% (0.05221) | 89.66th | v4 (v2025.03.14) |
| Dec 13, 2025 | 11.39% (0.11388) | 93.31th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.94% (0.04936) | 88.64th | v4 (v2025.03.14) |
| Mar 29, 2025 | 8.95% (0.08948) | 87.51th | v4 (v2025.03.14) |
| Mar 24, 2025 | 4.94% (0.04936) | 88.63th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.49% (0.03492) | 86.80th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.49% (0.00494) | 76.97th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.49% (0.00494) | 75.48th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.49% (0.00494) | 72.49th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.53% (0.02528) | 81.92th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.53% (0.02528) | 80.15th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.53% (0.02528) | 58.66th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.81% (0.00814) | 22.17th | v1 |
| Jan 6, 2022 | 0.81% (0.00814) | 21.57th | v1 |
| Sep 1, 2021 | 0.81% (0.00814) | 52.13th | v1 |
| Jul 13, 2021 | 0.81% (0.00814) | 0.00th | v1 |
| Jun 10, 2021 | 0.31% (0.00310) | 0.00th | v1 |
| Jun 9, 2021 | 2.08% (0.02080) | 0.00th | v1 |
| Apr 14, 2021 | 1.82% (0.01823) | 0.00th | v1 |
References (24)
- http://packetstormsecurity.com/files/142284/Slackware-Security-Advisory-ntp-Updates.html x_refsource_MISC
- http://seclists.org/fulldisclosure/2017/Nov/7 mailing-listx_refsource_FULLDISC
- http://seclists.org/fulldisclosure/2017/Sep/62 mailing-listx_refsource_FULLDISC
- http://support.ntp.org/bin/view/Main/NtpBug3379 x_refsource_CONFIRMPatchVendor Advisory
- http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secu x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/archive/1/archive/1/540464/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/97051 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038123 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-3349-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2017-6458 Vendor Advisory
- https://bto.bluecoat.com/security-advisory/sa147 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=1434005 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdf x_refsource_CONFIRMThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4B7BMVXV53EE7XYW2KAVETDHTP452O3Z/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7KVLFA3J43QFIP4I7HE7KQ5FXSMJEKC6/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZUPPICJXWL3AWQB7I3AWUC74YON7UING/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2017-6458
- https://support.apple.com/HT208144 x_refsource_CONFIRMThird Party Advisory
- https://support.apple.com/kb/HT208144 x_refsource_CONFIRM
- https://support.f5.com/csp/article/K99254031 x_refsource_CONFIRM
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us x_refsource_CONFIRMThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-159-11 x_refsource_MISC
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-294/ x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2017-6458
Change history (0)
No recorded changes yet.