CVE-2017-6458: Apple Mac OS X

High severity, CVSS 8.8. EPSS: 6.5% chance of exploitation in the next 30 days.

Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.

Affected products

  • Apple Mac OS X: from 10.8.0, before 10.13 (fixed in 10.13)
  • HPE Hpux-Ntp: before c.4.2.8.4.0 (fixed in c.4.2.8.4.0)
  • Ntp Ntp: before 4.2.8 (fixed in 4.2.8); from 4.3.0, before 4.3.94 (fixed in 4.3.94); version 4.2.8 only
  • Siemens SIMATIC Net CP 443-1 Opc Ua Firmware: any version

Published 2017-03-27. Last modified 2026-06-17.