PT-2019-4219 · Ntpsec+1 · Ntpsec+1
Magnus Klaaborg Stubman
+1
·
Publicado
2019-01-15
·
Atualizado
2024-06-15
·
CVE-2019-6442
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
NTPsec versions prior to 1.1.3
Description
An issue in NTPsec allows an authenticated attacker to write one byte out of bounds in ntpd via a malformed config request. This is related to functions such as
config remotely in ntp config.c, yyparse in ntp parser.tab.c, and yyerror in ntp parser.y. The vulnerability can be exploited by a remote attacker using an improperly formatted configuration request, potentially leading to a denial of service.Recommendations
For versions prior to 1.1.3, update to version 1.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the config request functionality to minimize the risk of exploitation.
Exploit
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ntpsec
Suse