CVE-2023-26551: Medium severity ntp vulnerability
Published Apr 11, 2023
·Updated
mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
Affected Software
1 affected component
NTP ntp=4.2.8-p15
Event History
Apr 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-26551?
The severity of CVE-2023-26551 is medium with a CVSS score of 5.6.
2
How does CVE-2023-26551 affect NTP?
CVE-2023-26551 affects NTP version 4.2.8p15.
3
What is the CWE ID of CVE-2023-26551?
The CWE ID of CVE-2023-26551 is CWE-787.
4
What is the fix for CVE-2023-26551?
To fix CVE-2023-26551, upgrade NTP to version 4.2.8p16 or later.
5
Is it possible to attack the ntpq process with CVE-2023-26551?
No, an adversary cannot attack the ntpq process with CVE-2023-26551.