#VU14423 Information disclosure in Network Time Protocol - CVE-2014-5209
Published: August 14, 2018 / Updated: August 16, 2018
Network Time Protocol
ntp.org
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to an error when handling malicious input. A remote attacker can send a specially crafted GET_RESTRICT control message and gain access to internal or alternative IP addresses and other sensitive information.