Back

MEDIUM

ntp: an out-of-bounds write when adding a '\0' character

Published Apr 11, 2023

Description

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 11, 2023
Updated Feb 11, 2025
Reserved Feb 25, 2023
CISA Vulnrichment
Updated Feb 11, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 12, 2023