#VU17183 Stack out-of-bounds read in NTPsec - CVE-2019-6444
Published: January 24, 2019 / Updated: June 17, 2021
NTPsec
The NTPsec project
Description
The vulnerability allows a remote authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to attacker-controlled data is dereferenced by ntohl() in ntpd. A remote attacker can trigger stack-based buffer over-read in process_control() in ntp_control.c perform a denial of service attack.