mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
References
Link | Resource |
---|---|
https://github.com/spwpun/ntp-4.2.8p15-cves/blob/main/CVE-2023-26552 | Third Party Advisory |
https://github.com/spwpun/ntp-4.2.8p15-cves/issues/1#issuecomment-1506667321 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-04-11T00:00:00
Updated: 2023-04-13T00:00:00
Reserved: 2023-02-25T00:00:00
Link: CVE-2023-26552
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-04-11T21:15:21.660
Modified: 2023-04-20T14:37:43.543
Link: CVE-2023-26552
JSON object: View
Redhat Information
No data.
CWE