Description
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.
Published: 2009-12-09
Score: 6.4 Medium
EPSS: 81.1% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1948-1 New ntp packages fix denial of service
Debian DSA Debian DSA DSA-1992-1 New chrony packages fix denial of service
Ubuntu USN Ubuntu USN USN-867-1 Ntp vulnerability
References
Link Providers
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2010-005.txt.asc cve-icon cve-icon
http://aix.software.ibm.com/aix/efixes/security/xntpd_advisory.asc cve-icon cve-icon
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560074 cve-icon cve-icon
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673 cve-icon cve-icon
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10691 cve-icon cve-icon
http://lists.vmware.com/pipermail/security-announce/2010/000082.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=130168580504508&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=136482797910018&w=2 cve-icon cve-icon
http://secunia.com/advisories/37629 cve-icon cve-icon
http://secunia.com/advisories/37922 cve-icon cve-icon
http://secunia.com/advisories/38764 cve-icon cve-icon
http://secunia.com/advisories/38794 cve-icon cve-icon
http://secunia.com/advisories/38832 cve-icon cve-icon
http://secunia.com/advisories/38834 cve-icon cve-icon
http://secunia.com/advisories/39593 cve-icon cve-icon
http://security-tracker.debian.org/tracker/CVE-2009-3563 cve-icon cve-icon
http://securitytracker.com/id?1023298 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021781.1-1 cve-icon cve-icon
http://support.avaya.com/css/P8/documents/100071808 cve-icon cve-icon
http://support.ntp.org/bin/view/Main/SecurityNotice#DoS_attack_from_certain_NTP_mode cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ68659 cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ71047 cve-icon cve-icon
http://www.debian.org/security/2009/dsa-1948 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/568372 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/MAPG-7X7V6J cve-icon cve-icon
http://www.kb.cert.org/vuls/id/MAPG-7X7VD7 cve-icon cve-icon
http://www.securityfocus.com/bid/37255 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0510 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0528 cve-icon cve-icon
http://www.vupen.com/english/advisories/2010/0993 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=531213 cve-icon cve-icon
https://lists.ntp.org/pipermail/announce/2009-December/000086.html cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2009-3563 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11225 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12141 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19376 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7076 cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2009-1648.html cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2009-1651.html cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2010-0095.html cve-icon cve-icon
https://support.ntp.org/bugs/show_bug.cgi?id=1331 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2009-3563 cve-icon
https://www.kb.cert.org/vuls/id/417980 cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00763.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00809.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T06:31:10.550Z

Reserved: 2009-10-05T00:00:00.000Z

Link: CVE-2009-3563

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-12-09T18:30:00.390

Modified: 2026-04-23T00:35:47.467

Link: CVE-2009-3563

cve-icon Redhat

Severity : Moderate

Publid Date: 2009-12-08T00:00:00Z

Links: CVE-2009-3563 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses