Логотип exploitDog
bind:CVE-2023-33192
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-33192

Количество 2

Количество 2

nvd логотип

CVE-2023-33192

больше 2 лет назад

ntpd-rs is an NTP implementation written in Rust. ntpd-rs does not validate the length of NTS cookies in received NTP packets to the server. An attacker can crash the server by sending a specially crafted NTP packet containing a cookie shorter than what the server expects. The server also crashes when it is not configured to handle NTS packets. The issue was caused by improper slice indexing. The indexing operations were replaced by safer alternatives that do not crash the ntpd-rs server process but instead properly handle the error condition. A patch was released in version 0.3.3.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-qwhm-h7v3-mrjx

больше 2 лет назад

Improper handling of NTS cookie length that could crash the ntpd-rs server

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-33192

ntpd-rs is an NTP implementation written in Rust. ntpd-rs does not validate the length of NTS cookies in received NTP packets to the server. An attacker can crash the server by sending a specially crafted NTP packet containing a cookie shorter than what the server expects. The server also crashes when it is not configured to handle NTS packets. The issue was caused by improper slice indexing. The indexing operations were replaced by safer alternatives that do not crash the ntpd-rs server process but instead properly handle the error condition. A patch was released in version 0.3.3.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-qwhm-h7v3-mrjx

Improper handling of NTS cookie length that could crash the ntpd-rs server

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу