CVE-2019-6442 PUBLISHED

An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y.

EPSS 10.20% · 93.1th percentile

Risk Scores

EPSS Score
10.20%
93.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSntpsec0, 1.0.0+dfsg1-1, 1.0.0+dfsg1-3

Timeline

References

Open in Interactive Console →