Description

Customer reports that the Scanning Tool indicates vulnerability for CVE-2009-1252.

Symptoms

Scanning Tool indicates a false positive for CVE-2009-1252, regardless of the Junos code.

The ntpd(8) daemon is prone to a stack-based buffer-overflow when it is configured to use the 'autokey' security model. 

Solution

Fixed from junos:9.3R4 junos:9.4R4 junos:9.5R3 junos:9.6R2 junos:10.0R1 junos:10.1R1

It is also resolved on the subsequent releases.

 

Related PR:

FreeBSD-SA-09:11.ntpd - ntpd stack-based buffer-overflow vulnerability (CVE-2009-1252)

https://prsearch.juniper.net/problemreport/PR452678

 

There is no vulnerability here, the CVE isn’t material to Junos OS – it’s a false positive – and there is nothing to do. We have proved it is the scanner – we know our source code.

The scanner is only checking a version header. It is a false positive. Further, if the customer is running this scanner in a locally authenticated way to the system that is a problem in that they are exposing themselves to local authentication attacks against ntpq / ntpd. They should not be doing so. 

Modification History

7/18/2023