Customer reports that the Scanning Tool indicates vulnerability for CVE-2009-1252.
Scanning Tool indicates a false positive for CVE-2009-1252, regardless of the Junos code.
The ntpd(8) daemon is prone to a stack-based buffer-overflow when it is configured to use the 'autokey' security model.
Fixed from junos:9.3R4 junos:9.4R4 junos:9.5R3 junos:9.6R2 junos:10.0R1 junos:10.1R1
It is also resolved on the subsequent releases.
Related PR:
FreeBSD-SA-09:11.ntpd - ntpd stack-based buffer-overflow vulnerability (CVE-2009-1252)
https://prsearch.juniper.net/problemreport/PR452678
There is no vulnerability here, the CVE isn’t material to Junos OS – it’s a false positive – and there is nothing to do. We have proved it is the scanner – we know our source code.
The scanner is only checking a version header. It is a false positive. Further, if the customer is running this scanner in a locally authenticated way to the system that is a problem in that they are exposing themselves to local authentication attacks against ntpq / ntpd. They should not be doing so.
7/18/2023