CVE-2019-6443: Critical severity ntpsec vulnerability
Published Jan 16, 2019
·Updated
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctlgetitem, there is a stack-based buffer over-read in readsysvars in ntpcontrol.c in ntpd.
Affected Software
1 affected component
NTPsec NTPsec<1.1.3
Event History
Jan 16, 2019
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-6443?
CVE-2019-6443 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2019-6443?
To fix CVE-2019-6443, upgrade NTPsec to version 1.1.3 or later.
3
What type of vulnerability is CVE-2019-6443?
CVE-2019-6443 is a stack-based buffer over-read vulnerability.
4
In which component does CVE-2019-6443 occur?
CVE-2019-6443 occurs in the read_sysvars function in ntp_control.c in NTPsec.
5
Which versions of NTPsec are affected by CVE-2019-6443?
NTPsec versions prior to 1.1.3 are affected by CVE-2019-6443.