QID 996203
Date Published: 2023-12-13
QID 996203: Rust (Rust) Security Update for ntpd (GHSA-qwhm-h7v3-mrjx)
ntpd-rs does not validate the length of NTS cookies in received NTP packets to the server. An attacker can crash the server by sending a specially crafted NTP packet containing a cookie shorter than what the server expects. The server also crashes when it is not configured to handle NTS packets.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qwhm-h7v3-mrjx for updates and patch information.
Vendor References
- GHSA-qwhm-h7v3-mrjx -
github.com/advisories/GHSA-qwhm-h7v3-mrjx
CVEs related to QID 996203
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qwhm-h7v3-mrjx | ntpd |
|