vendor:
N/A
by:
patrick
N/A
CVSS
N/A
Buffer Overflow
120
CWE
Product Name: N/A
Affected Version From: RedHat Linux 7.0 ntpd 4.0.99j
Affected Version To: RedHat Linux 7.0 ntpd 4.0.99k
Patch Exists: NO
Related CWE: CVE-2001-0414, OSVDB-805, BID-2540, US-CERT-VU-970472
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2010
NTP daemon readvar Buffer Overflow
This module exploits a stack based buffer overflow in the ntpd and xntpd service. By sending an overly long 'readvar' request it is possible to execute code remotely. As the stack is corrupted, this module uses the Egghunter technique.
Mitigation:
None