First published: Wed Jan 16 2019(Updated: )
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_control.c in ntpd.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NTPsec | <1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6443 has been classified as a medium severity vulnerability.
To fix CVE-2019-6443, upgrade NTPsec to version 1.1.3 or later.
CVE-2019-6443 is a stack-based buffer over-read vulnerability.
CVE-2019-6443 occurs in the read_sysvars function in ntp_control.c in NTPsec.
NTPsec versions prior to 1.1.3 are affected by CVE-2019-6443.