PT-2019-4219 · Ntpsec+1 · Ntpsec+1

Magnus Klaaborg Stubman

+1

·

Published

2019-01-15

·

Updated

2024-06-15

·

CVE-2019-6442

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions NTPsec versions prior to 1.1.3
Description An issue in NTPsec allows an authenticated attacker to write one byte out of bounds in ntpd via a malformed config request. This is related to functions such as config remotely in ntp config.c, yyparse in ntp parser.tab.c, and yyerror in ntp parser.y. The vulnerability can be exploited by a remote attacker using an improperly formatted configuration request, potentially leading to a denial of service.
Recommendations For versions prior to 1.1.3, update to version 1.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the config request functionality to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04816
CVE-2019-6442
OPENSUSE-SU-2019:0082-1
OPENSUSE-SU-2019_0082-1
OPENSUSE-SU-2024:11103-1

Affected Products

Ntpsec
Suse