Oval Definition:
oval:org.mitre.oval:def:3831
Revision Date
:
2005-06-01
Version
:
16
Title
:
Buffer Overflow in ntp Daemon via readvar
Description
:
Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.
Family
:
unix
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2001-0414
Platform(s)
:
Sun Solaris 7
Sun Solaris 8
Product(s)
:
sendfilev()
Definition Synopsis
Software section
Solaris 7 or 8 installed
Solaris 7 Installed
OR
Solaris 8 Installed
AND
NTP daemon - Usr (SUNWntpu) installed
AND
NOT
Patch 109409-04 or later installed
AND
NOT
Patch 109667-04 or later installed
AND
Configuration section
xntpd running
BACK