Use of uninitialized resource in NTPsec - CVE-2023-4012
Published: August 6, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to usage of uninitialized resources in ntpd/nts_cookie.c when processing NTS requests in a server with disabled NTS support. A remote attacker can send an NTS-enabled client request (mode 3) to the server and perform a denial of service (DoS) attack.
Affected software
Debian Linux
Fedora
ntpsec
ntpsec (Debian package)
How to mitigate CVE-2023-4012
ntpsec - addressed in versions 1.2.2a-1.el9, 1.2.2a-1.fc37, 1.2.2a-1.fc38
ntpsec (Debian package) - update to 1.2.2+dfsg1-1+deb12u1