CVE-2019-6444: Critical severity ntpsec vulnerability
Published Jan 16, 2019
·Updated
An issue was discovered in NTPsec before 1.1.3. processcontrol() in ntpcontrol.c has a stack-based buffer over-read because attacker-controlled data is dereferenced by ntohl() in ntpd.
Affected Software
1 affected component
NTPsec NTPsec<1.1.3
Event History
Jan 16, 2019
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-6444?
CVE-2019-6444 is classified as a medium severity vulnerability.
2
How does CVE-2019-6444 affect NTPsec?
CVE-2019-6444 allows an attacker to perform a stack-based buffer over-read through crafted data.
3
What versions of NTPsec are affected by CVE-2019-6444?
CVE-2019-6444 affects NTPsec versions before 1.1.3.
4
How can I mitigate CVE-2019-6444?
You can mitigate CVE-2019-6444 by upgrading to NTPsec version 1.1.3 or later.
5
What is the nature of the vulnerability in CVE-2019-6444?
CVE-2019-6444 involves the dereferencing of attacker-controlled data which leads to a buffer over-read.