---
cve: "CVE-2013-5211"
severity: "LOW"
cvss: 3.1
epss: "97.6%"
vendor: "n/a"
kev: false
exploited: false
published: "2014-01-02 14:59:03"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T05:38:22+02:00"
---

# CVE-2013-5211

> 3.1 LOW

## Beschreibung

The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.

## Exploit-Evidenz

- [EDB-33073 — NTP ntpd monlist Query Reflection - Denial of Service](https://www.exploit-db.com/exploits/33073)

## Referenzen

- <http://secunia.com/advisories/59288>
- <https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04790232>
- <http://lists.opensuse.org/opensuse-updates/2014-09/msg00031.html>
- <http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html>
- <http://marc.info/?l=bugtraq&m=138971294629419&w=2>
- <http://www.us-cert.gov/ncas/alerts/TA14-013A>
- <http://www.securityfocus.com/bid/64692>
- <http://www.kb.cert.org/vuls/id/348126>
- <http://marc.info/?l=bugtraq&m=144182594518755&w=2>
- <http://openwall.com/lists/oss-security/2013/12/30/6>
- <http://secunia.com/advisories/59726>
- <http://www.securitytracker.com/id/1030433>
- <http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-dev/ntp-dev-4.2.7p26.tar.gz>
- <http://ics-cert.us-cert.gov/advisories/ICSA-14-051-04>
- <http://aix.software.ibm.com/aix/efixes/security/ntp_advisory.asc>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2013-5211) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
