An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, related to ctl_getitem.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HNtpsec
APPNtpsec< 1.1.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2019-6443CRITICAL9.1PL ✓same product
Stack-based buffer over-read w NTPsec — odczyt pamięci i DoS
CVE-2019-6444CRITICAL9.1PL ✓same product
NTPsec: stack-based buffer over-read w process_control() przez ntohl()
CVE-2023-4012HIGH7.5same product
ntpd will crash if the server is not NTS-enabled (no certificate) and it receives an NTS-enabled client reques...
CVE-2021-22212MEDIUM4.0same product
ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' ...
CVE-2019-6442MEDIUM6.5same product
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ...