PT-2023-22652 · Cloudflare · Cfnts
00Xc
+1
·
Published
2023-06-14
·
Updated
2023-06-27
·
CVE-2023-3036
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
github.com/cloudflare/cfnts versions prior to commit 783490b
Description
The issue is related to an unchecked read in the NTP server, which allows a remote attacker to trigger a panic by sending an NTSAuthenticator packet with an extension length longer than the packet contents.
Recommendations
For versions prior to commit 783490b, update to a version that includes the fix for this issue, specifically commit 783490b or later. As a temporary workaround, consider restricting access to the NTP server to minimize the risk of exploitation.
Fix
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cfnts