GHSA-37xq-q42p-rv3p
Dashboard / Vulnerabilities / GHSA-37xq-q42p-rv3p
GHSA-37xq-q42p-rv3p
Summary: ntpd has Dependency on Vulnerable Third-Party Component
Details: During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ### Impact This vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS ### Patches Affected users are recommended to upgrade to version 0.3.7 ### References See also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md
References: https://github.com/pendulum-project/ntpd-rs/security/advisories/GHSA-37xq-q42p-rv3p, https://github.com/pendulum-project/ntpd-rs/commit/927952a440176a18f3ded132eb831ae7f7ac5c00, https://github.com/pendulum-project/ntpd-rs, https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md
Affected packages
Package
Name: ntpd
Purl: pkg:cargo/ntpd
Affected ranges
Type: SEMVER
Events:
