First published: Mon Mar 27 2017(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org Cure53 Cure53 Cure53 Cure53 Cure53 Cure53 Cure53 Cure53 Cure53 Matthew Van Gundy Cisco cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS High Sierra | <10.13 | 10.13 |
Siemens SIMATIC NET CP 443-1 OPC UA | ||
NTP ntp | <4.2.8 | |
NTP ntp | >=4.3.0<4.3.94 | |
NTP ntp | =4.2.8 | |
NTP ntp | =4.2.8-p1 | |
NTP ntp | =4.2.8-p1-beta1 | |
NTP ntp | =4.2.8-p1-beta2 | |
NTP ntp | =4.2.8-p1-beta3 | |
NTP ntp | =4.2.8-p1-beta4 | |
NTP ntp | =4.2.8-p1-beta5 | |
NTP ntp | =4.2.8-p1-rc1 | |
NTP ntp | =4.2.8-p1-rc2 | |
NTP ntp | =4.2.8-p2 | |
NTP ntp | =4.2.8-p2-rc1 | |
NTP ntp | =4.2.8-p2-rc2 | |
NTP ntp | =4.2.8-p2-rc3 | |
NTP ntp | =4.2.8-p3 | |
NTP ntp | =4.2.8-p3-rc1 | |
NTP ntp | =4.2.8-p3-rc2 | |
NTP ntp | =4.2.8-p3-rc3 | |
NTP ntp | =4.2.8-p4 | |
NTP ntp | =4.2.8-p5 | |
NTP ntp | =4.2.8-p6 | |
NTP ntp | =4.2.8-p7 | |
NTP ntp | =4.2.8-p8 | |
NTP ntp | =4.2.8-p9 | |
Hpe Hpux-ntp | <c.4.2.8.4.0 | |
Apple Mac OS X | >=10.8.0<10.13 | |
Siemens Simatic Net Cp 443-1 Opc Ua Firmware | ||
Siemens SIMATIC NET CP 443-1 OPC UA | ||
All of | ||
Siemens Simatic Net Cp 443-1 Opc Ua Firmware | ||
Siemens SIMATIC NET CP 443-1 OPC UA | ||
debian/ntp | 1:4.2.8p15+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2017-6458 is a vulnerability in NTP that allows remote authenticated users to have unspecified impact via a long variable.
CVE-2017-6458 has a severity rating of 8.8 (high).
To fix CVE-2017-6458, update NTP to version 4.2.8p10 or later.
You can find more information about CVE-2017-6458 at the following references: [http://support.ntp.org/bin/view/Main/NtpBug3379](http://support.ntp.org/bin/view/Main/NtpBug3379), [http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secu](http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secu), [http://www.securitytracker.com/id/1038123](http://www.securitytracker.com/id/1038123).
The CWE for CVE-2017-6458 is CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer).