CVE-2009-0021: Medium severity NTP ntp vulnerability
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVPVerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0021?
CVE-2009-0021 is classified as a high-severity vulnerability due to its potential to allow certificate chain validation bypass.
How do I fix CVE-2009-0021?
To fix CVE-2009-0021, upgrade to NTP version 4.2.4p5 or later, or 4.2.5p150 or later.
Which versions of NTP are affected by CVE-2009-0021?
CVE-2009-0021 affects NTP versions prior to 4.2.4p5 and 4.2.5 versions before 4.2.5p150.
What exploitation methods are possible with CVE-2009-0021?
Exploitation of CVE-2009-0021 could allow remote attackers to bypass SSL/TLS certificate validation by using malformed signatures.
What protocols are impacted by CVE-2009-0021?
CVE-2009-0021 specifically affects the DSA and ECDSA keys used in SSL/TLS communications.