First published: Wed Jun 14 2023(Updated: )
An unchecked read in NTP server in github.com/cloudflare/cfnts prior to commit 783490b https://github.com/cloudflare/cfnts/commit/783490b913f05e508a492cd7b02e3c4ec2297b71 enabled a remote attacker to trigger a panic by sending an NTSAuthenticator packet with extension length longer than the packet contents.
Credit: cna@cloudflare.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudflare Cfnts | <2023-06-01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-3036 is high with a severity score of 7.5.
CVE-2023-3036 allows a remote attacker to trigger a panic in Cloudflare Cfnts by sending an NTSAuthenticator packet with extension length longer than the packet.
The affected software for CVE-2023-3036 is Cloudflare Cfnts prior to commit 783490b.
To fix CVE-2023-3036, update Cloudflare Cfnts to version later than commit 783490b.
You can find more information about CVE-2023-3036 in the advisory published by Cloudflare: [link](https://github.com/cloudflare/cfnts/security/advisories/GHSA-pwx6-gw47-96cp).