CVE-2004-0657

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
06/08/2004
Last modified:
03/04/2025

Description

Integer overflow in the NTP daemon (NTPd) before 4.0 causes the NTP server to return the wrong date/time offset when a client requests a date/time that is more than 34 years away from the server's time.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* 4.0 (excluding)
cpe:2.3:o:hp:tru64_unix:4.0f:patch_kit8:*:*:*:*:*:*
cpe:2.3:o:hp:tru64_unix:4.0g:patch_kit4:*:*:*:*:*:*
cpe:2.3:o:hp:tru64_unix:5.1b:patch_kit2:*:*:*:*:*:*
cpe:2.3:o:hp:tru64_unix:5.1b:patch_kit3:*:*:*:*:*:*
cpe:2.3:o:hp:tru64_unix:5.1b:patch_kit4:*:*:*:*:*:*
cpe:2.3:o:hp:tru64_unix:51.1a:patch_kit6:*:*:*:*:*:*