CVE-2004-0657
Severity CVSS v4.0:
Pending analysis
Type:
CWE-190
Integer Overflow or Wraparound
Publication date:
06/08/2004
Last modified:
03/04/2025
Description
Integer overflow in the NTP daemon (NTPd) before 4.0 causes the NTP server to return the wrong date/time offset when a client requests a date/time that is more than 34 years away from the server's time.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* | 4.0 (excluding) | |
| cpe:2.3:o:hp:tru64_unix:4.0f:patch_kit8:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:tru64_unix:4.0g:patch_kit4:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:tru64_unix:5.1b:patch_kit2:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:tru64_unix:5.1b:patch_kit3:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:tru64_unix:5.1b:patch_kit4:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:tru64_unix:51.1a:patch_kit6:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



