CVE-2019-6442: Medium severity ntpsec vulnerability
Published Jan 16, 2019
·Updated
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to configremotely in ntpconfig.c, yyparse in ntpparser.tab.c, and yyerror in ntpparser.y.
Affected Software
1 affected component
NTPsec NTPsec<1.1.3
Event History
Jan 16, 2019
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-6442?
CVE-2019-6442 is classified as a medium severity vulnerability that can lead to out-of-bounds writes.
2
How do I fix CVE-2019-6442?
To fix CVE-2019-6442, upgrade NTPsec to version 1.1.3 or later.
3
What causes CVE-2019-6442?
CVE-2019-6442 is caused by a flaw in the ntpd component that allows authenticated attackers to send malformed config requests.
4
What are the potential impacts of CVE-2019-6442?
The potential impacts of CVE-2019-6442 include crashing the NTP service and exploiting the server through out-of-bounds writes.
5
Who is affected by CVE-2019-6442?
CVE-2019-6442 affects all versions of NTPsec prior to 1.1.3.