The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
2014-01-02T14:59:03.470
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | opensuse | opensuse | 11.4 | Yes |
Application | ntp | ntp | < 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Application | ntp | ntp | 4.2.7 | Yes |
Operating System | oracle | linux | 6 | Yes |
Operating System | oracle | linux | 7 | Yes |