CVE-2014-9296
EPSS 24.6%
Description
The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to execute after detecting a certain authentication error, which might allow remote attackers to trigger an unintended association change via crafted packets.
How to fix CVE-2014-9296
To remediate CVE-2014-9296, upgrade the affected package to a fixed version below.
- Debian/ntp—upgrade to 1:4.2.6.p5+dfsg-3.2 or later
Is CVE-2014-9296 being exploited?
Moderate — EPSS is 24.6%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1:4.2.6.p5+dfsg-3.2