First published: Tue Apr 11 2023(Updated: )
mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NTP ntp | =4.2.8-p15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-26553.
The severity of CVE-2023-26553 is medium with a CVSS score of 5.6.
CVE-2023-26553 affects NTP version 4.2.8p15.
The CWE ID associated with CVE-2023-26553 is CWE-787.
An adversary may be able to attack a client ntpq process, but cannot attack ntpd.