CVE-2024-38528Allocation of Resources Without Limits or Throttling in Mills Ntpd

Severity
7.5HIGHNVD
EPSS
0.2%
top 55.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 28

Description

nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing limit for accepted NTS-KE connections. This allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected. This vulnerability has been patched in version 1.1.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

crates.iodave_mills/ntpd0.3.11.1.3
debiandebian/rust-ntpd< rust-ntpd 1.1.3-1 (forky)
CVEListV5pendulum-project/ntpd-rs>= 0.3.1, <= 1.1.2

🔴Vulnerability Details

3
GHSA
Unlimited number of NTS-KE connections can crash ntpd-rs server2024-06-28
OSV
CVE-2024-38528: nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols2024-06-28
OSV
Unlimited number of NTS-KE connections can crash ntpd-rs server2024-06-28

📋Vendor Advisories

1
Debian
CVE-2024-38528: rust-ntpd - nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP ...2024