Back

HIGH

ntp: wrong date/time offset return could lead to integer overflow

Published Jul 13, 2004

Description

Integer overflow in the NTP daemon (NTPd) before 4.0 causes the NTP server to return the wrong date/time offset when a client requests a date/time that is more than 34 years away from the server's time.

Affected products

Remediation

Red Hat statement

As per the CERT advisory, this issue has been resolved by ntp version 4. All Red Hat products ship ntp-4, therefore there are not affected by this flaw.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 13, 2004
Updated Aug 8, 2024
Reserved Jul 9, 2004
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jun 18, 2020