405
VMScore

CVE-2019-6445

Published: 16/01/2019 Updated: 22/01/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

An issue exists in NTPsec prior to 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, related to ctl_getitem.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ntpsec ntpsec

Vendor Advisories

Debian Bug report logs - #919513 CVE-2019-6442 CVE-2019-6443 CVE-2019-6444 CVE-2019-6445 Package: src:ntpsec; Maintainer for src:ntpsec is Richard Laager <rlaager@wiktelcom>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 16 Jan 2019 19:24:02 UTC Severity: grave Tags: security Found in version ntpsec/1 ...

Exploits

#!/usr/bin/env python # Exploit Title: ntpsec 112 authenticated NULL pointer exception Proof of concept # Bug Discovery: Magnus Klaaborg Stubman (@magnusstubman) # Exploit Author: Magnus Klaaborg Stubman (@magnusstubman) # Website: dumpcore/bugs/ntpsec-authed-npe # Vendor Homepage: ntpsecorg/ # Software Link: ftp://ftpntpsec ...
NTPsec version 112 suffer from a null pointer dereference vulnerability in ntp_control ...