PT-2019-4219 · Ntpsec+1 · Ntpsec+1

Magnus Klaaborg Stubman

+1

·

Publicado

2019-01-15

·

Atualizado

2024-06-15

·

CVE-2019-6442

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions NTPsec versions prior to 1.1.3
Description An issue in NTPsec allows an authenticated attacker to write one byte out of bounds in ntpd via a malformed config request. This is related to functions such as config remotely in ntp config.c, yyparse in ntp parser.tab.c, and yyerror in ntp parser.y. The vulnerability can be exploited by a remote attacker using an improperly formatted configuration request, potentially leading to a denial of service.
Recommendations For versions prior to 1.1.3, update to version 1.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the config request functionality to minimize the risk of exploitation.

Exploit

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-04816
CVE-2019-6442
OPENSUSE-SU-2019:0082-1
OPENSUSE-SU-2019_0082-1
OPENSUSE-SU-2024:11103-1

Produtos afetados

Ntpsec
Suse