CVE-2023-4012

Name
CVE-2023-4012
Description
ntpd will crash if the server is not NTS-enabled (no certificate) and it receives an NTS-enabled client request (mode 3).
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://gitlab.com/NTPsec/ntpsec/-/issues/794
MISC https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038422
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VQDOZSTH2AZXBO2QAVR2SZEMK2A7WBRB/
MISC https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OC2KDNL4GO7MDAFSNWBQA4T2Q2VNPUJD/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:ntpsec:ntpsec:1.2.2:*:*:*:*:*:*:* ntpsec == None == 1.2.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ntpsec edge-community 1.2.2a-r0 Hoang Nguyen <folliekazetani@protonmail.com> fixed
ntpsec 3.22-community 1.2.2a-r0 None fixed
ntpsec 3.21-community 1.2.2a-r0 None fixed
ntpsec 3.20-community 1.2.2a-r0 None fixed
ntpsec 3.19-community 1.2.2a-r0 Hoang Nguyen <folliekazetani@protonmail.com> fixed
ntpsec 3.18-community 1.2.2a-r0 Hoang Nguyen <folliekazetani@protonmail.com> fixed