CVE-2023-3036: Out of Bounds Slice index in cfnts leads to remote panic
An unchecked read in NTP server in github.com/cloudflare/cfnts prior to commit 783490b https://github.com/cloudflare/cfnts/commit/783490b913f05e508a492cd7b02e3c4ec2297b71 enabled a remote attacker to trigger a panic by sending an NTSAuthenticator packet with extension length longer than the packet contents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3036?
The severity of CVE-2023-3036 is high with a severity score of 7.5.
How does CVE-2023-3036 impact Cloudflare Cfnts?
CVE-2023-3036 allows a remote attacker to trigger a panic in Cloudflare Cfnts by sending an NTSAuthenticator packet with extension length longer than the packet.
What is the affected software for CVE-2023-3036?
The affected software for CVE-2023-3036 is Cloudflare Cfnts prior to commit 783490b.
How can I fix CVE-2023-3036?
To fix CVE-2023-3036, update Cloudflare Cfnts to version later than commit 783490b.
Where can I find more information about CVE-2023-3036?
You can find more information about CVE-2023-3036 in the advisory published by Cloudflare: [link](https://github.com/cloudflare/cfnts/security/advisories/GHSA-pwx6-gw47-96cp).