Unrated severityNVD Advisory· Published Apr 14, 2009· Updated Apr 23, 2026
CVE-2009-0159
CVE-2009-0159
Description
Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.
Affected products
30cpe:2.3:a:ntp:ntp:4.0.72:*:*:*:*:*:*:*+ 28 more
- cpe:2.3:a:ntp:ntp:4.0.72:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.0.73:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.0.90:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.0.91:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.0.92:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.0.93:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.0.94:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.0.95:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.0.96:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.0.97:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.0.98:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.0.99:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.2p1:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.2p2:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.2p3:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.2p4:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.4p0:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.4p1:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.4p2:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.4p3:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.4p4:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.4p5:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.4p6:*:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:*:rc1:*:*:*:*:*:*range: <=4.2.4p7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
46- www.securityfocus.com/bid/34481nvdPatch
- support.ntp.org/bugs/show_bug.cginvdPatch
- secunia.com/advisories/34608nvdVendor Advisory
- secunia.com/advisories/35074nvdVendor Advisory
- secunia.com/advisories/35137nvdVendor Advisory
- secunia.com/advisories/35138nvdVendor Advisory
- secunia.com/advisories/35166nvdVendor Advisory
- secunia.com/advisories/35169nvdVendor Advisory
- secunia.com/advisories/35253nvdVendor Advisory
- secunia.com/advisories/35308nvdVendor Advisory
- secunia.com/advisories/35336nvdVendor Advisory
- secunia.com/advisories/35416nvdVendor Advisory
- secunia.com/advisories/35630nvdVendor Advisory
- secunia.com/advisories/37471nvdVendor Advisory
- www.vupen.com/english/advisories/2009/0999nvdVendor Advisory
- www.vupen.com/english/advisories/2009/1297nvdVendor Advisory
- www.vupen.com/english/advisories/2009/3316nvdVendor Advisory
- www.us-cert.gov/cas/techalerts/TA09-133A.htmlnvdUS Government Resource
- ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-006.txt.ascnvd
- bugs.pardus.org.tr/show_bug.cginvd
- lists.apple.com/archives/security-announce/2009/May/msg00002.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlnvd
- marc.infonvd
- ntp.bkbits.net:8080/ntp-stable/nvd
- osvdb.org/53593nvd
- rhn.redhat.com/errata/RHSA-2009-1039.htmlnvd
- rhn.redhat.com/errata/RHSA-2009-1040.htmlnvd
- slackware.com/security/viewer.phpnvd
- support.apple.com/kb/HT3549nvd
- www.debian.org/security/2009/dsa-1801nvd
- www.gentoo.org/security/en/glsa/glsa-200905-08.xmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/archive/1/507985/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.vmware.com/security/advisories/VMSA-2009-0016.htmlnvd
- bugzilla.redhat.com/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/49838nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19392nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5411nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8386nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8665nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9634nvd
- rhn.redhat.com/errata/RHSA-2009-1651.htmlnvd
- usn.ubuntu.com/777-1/nvd
- www.redhat.com/archives/fedora-package-announce/2009-May/msg01414.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-May/msg01449.htmlnvd
News mentions
0No linked articles in our index yet.