CVE-2019-8936

NTP through 4.2.8p12 has a NULL Pointer Dereference.
References
Link Resource
http://bugs.ntp.org/show_bug.cgi?id=3565 Exploit Issue Tracking Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00032.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00036.html Mailing List Third Party Advisory
http://packetstormsecurity.com/files/152915/FreeBSD-Security-Advisory-FreeBSD-SA-19-04.ntp.html Third Party Advisory VDB Entry
http://support.ntp.org/bin/view/Main/SecurityNotice Release Notes Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NVS2CSG2TQ663CXOZZUJN4STQPMENNP/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBGXY7OKWOLT6X6JAPVZRFEP4FLCGGST/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQDNHNYOJK2SRSGO23GQ2RXTOUY2HLNN/
https://seclists.org/bugtraq/2019/May/39 Issue Tracking Mailing List Third Party Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-19:04.ntp.asc Mitigation Third Party Advisory
https://security.gentoo.org/glsa/201903-15 Third Party Advisory
https://security.netapp.com/advisory/ntap-20190503-0001/ Patch Third Party Advisory
https://support.f5.com/csp/article/K61363039 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us Third Party Advisory
https://usn.ubuntu.com/4563-1/
http://bugs.ntp.org/show_bug.cgi?id=3565 Exploit Issue Tracking Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00032.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00036.html Mailing List Third Party Advisory
http://packetstormsecurity.com/files/152915/FreeBSD-Security-Advisory-FreeBSD-SA-19-04.ntp.html Third Party Advisory VDB Entry
http://support.ntp.org/bin/view/Main/SecurityNotice Release Notes Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NVS2CSG2TQ663CXOZZUJN4STQPMENNP/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBGXY7OKWOLT6X6JAPVZRFEP4FLCGGST/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQDNHNYOJK2SRSGO23GQ2RXTOUY2HLNN/
https://seclists.org/bugtraq/2019/May/39 Issue Tracking Mailing List Third Party Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-19:04.ntp.asc Mitigation Third Party Advisory
https://security.gentoo.org/glsa/201903-15 Third Party Advisory
https://security.netapp.com/advisory/ntap-20190503-0001/ Patch Third Party Advisory
https://support.f5.com/csp/article/K61363039 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us Third Party Advisory
https://usn.ubuntu.com/4563-1/
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:netapp:clustered_data_ontap:*:*:*:*:*:*:*:*
cpe:2.3:o:netapp:data_ontap:-:*:*:*:*:7-mode:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:hpe:hpux-ntp:*:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:-:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-beta1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-beta2:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-beta3:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-beta4:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-beta5:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p1-rc2:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p10:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p11:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p12:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p2:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p2-rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p2-rc2:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p2-rc3:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p3:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p3-rc1:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p3-rc2:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p3-rc3:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p4:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p5:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p6:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p7:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p8:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.8:p9:*:*:*:*:*:*

History

21 Nov 2024, 04:50

Type Values Removed Values Added
References () http://bugs.ntp.org/show_bug.cgi?id=3565 - Exploit, Issue Tracking, Vendor Advisory () http://bugs.ntp.org/show_bug.cgi?id=3565 - Exploit, Issue Tracking, Vendor Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00032.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00032.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00036.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00036.html - Mailing List, Third Party Advisory
References () http://packetstormsecurity.com/files/152915/FreeBSD-Security-Advisory-FreeBSD-SA-19-04.ntp.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/152915/FreeBSD-Security-Advisory-FreeBSD-SA-19-04.ntp.html - Third Party Advisory, VDB Entry
References () http://support.ntp.org/bin/view/Main/SecurityNotice - Release Notes, Vendor Advisory () http://support.ntp.org/bin/view/Main/SecurityNotice - Release Notes, Vendor Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NVS2CSG2TQ663CXOZZUJN4STQPMENNP/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2NVS2CSG2TQ663CXOZZUJN4STQPMENNP/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBGXY7OKWOLT6X6JAPVZRFEP4FLCGGST/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JBGXY7OKWOLT6X6JAPVZRFEP4FLCGGST/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQDNHNYOJK2SRSGO23GQ2RXTOUY2HLNN/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQDNHNYOJK2SRSGO23GQ2RXTOUY2HLNN/ -
References () https://seclists.org/bugtraq/2019/May/39 - Issue Tracking, Mailing List, Third Party Advisory () https://seclists.org/bugtraq/2019/May/39 - Issue Tracking, Mailing List, Third Party Advisory
References () https://security.FreeBSD.org/advisories/FreeBSD-SA-19:04.ntp.asc - Mitigation, Third Party Advisory () https://security.FreeBSD.org/advisories/FreeBSD-SA-19:04.ntp.asc - Mitigation, Third Party Advisory
References () https://security.gentoo.org/glsa/201903-15 - Third Party Advisory () https://security.gentoo.org/glsa/201903-15 - Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20190503-0001/ - Patch, Third Party Advisory () https://security.netapp.com/advisory/ntap-20190503-0001/ - Patch, Third Party Advisory
References () https://support.f5.com/csp/article/K61363039 - Third Party Advisory () https://support.f5.com/csp/article/K61363039 - Third Party Advisory
References () https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us - Third Party Advisory () https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us - Third Party Advisory
References () https://usn.ubuntu.com/4563-1/ - () https://usn.ubuntu.com/4563-1/ -

Information

Published : 2019-05-15 16:29

Updated : 2024-11-21 04:50


NVD link : CVE-2019-8936

Mitre link : CVE-2019-8936

CVE.ORG link : CVE-2019-8936


JSON object : View

Products Affected

fedoraproject

  • fedora

ntp

  • ntp

hpe

  • hpux-ntp

opensuse

  • leap

netapp

  • data_ontap
  • clustered_data_ontap
CWE
CWE-476

NULL Pointer Dereference