Logo
componentntp
Name
ntp
Version
4.2.8p15
Type
library
Description
Network Time Protocol daemon and utilities
Licenses
NTP
PURL
-
CPE
cpe:2.3:*:ntp:ntp:4.2.8p15:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
4.2.8p18
scarthgap
4.2.8p17

Patches#


#
Title
Author
Resolve
1
Patch #1
Unknown
2
Patch #2
Koen Kooi <koen@dominion.thruhere.net>
3
test: Fix build with new compiler defaults to -fno-common
Khem Raj <raj.khem@gmail.com>
4
Patch #4
Peter Marko <peter.marko@siemens.com>
CVE-2023-26551
CVE-2023-26552
CVE-2023-26553
CVE-2023-26554
CVE-2023-26555
5
libntp: Do not use PTHREAD_STACK_MIN on glibc
Khem Raj <raj.khem@gmail.com>

Vulnerabilities#


Name
Analysis
Description
Patched
praecis_parse in ntpd/refclock_palisade.c in NTP 4.2.8p15 has an out-of-bounds write. Any attack method would be complex, e.g., with a manipulated GPS receiver.
Patched
mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
Patched
mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
Patched
mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
Patched
mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.