An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data is dereferenced by ntohl() in ntpd.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HNtpsec
APPNtpsec< 1.1.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2019-6443CRITICAL9.1PL ✓same product
Stack-based buffer over-read w NTPsec — odczyt pamięci i DoS
CVE-2023-4012HIGH7.5same product
ntpd will crash if the server is not NTS-enabled (no certificate) and it receives an NTS-enabled client reques...
CVE-2021-22212MEDIUM4.0same product
ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' ...
CVE-2019-6442MEDIUM6.5same product
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ...
CVE-2019-6445MEDIUM6.5same product
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference...