An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HNtpsec
APPNtpsec< 1.1.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje
Powiązane podatności
CVE-2019-6443CRITICAL9.1PL ✓ten sam produkt
Stack-based buffer over-read w NTPsec — odczyt pamięci i DoS
CVE-2019-6444CRITICAL9.1PL ✓ten sam produkt
NTPsec: stack-based buffer over-read w process_control() przez ntohl()
CVE-2023-4012HIGH7.5ten sam produkt
ntpd will crash if the server is not NTS-enabled (no certificate) and it receives an NTS-enabled client reques...
CVE-2021-22212MEDIUM4.0ten sam produkt
ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' ...
CVE-2019-6445MEDIUM6.5ten sam produkt
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference...