GHSA-37xq-q42p-rv3p

    Dashboard / Vulnerabilities / GHSA-37xq-q42p-rv3p

    GHSA-37xq-q42p-rv3p

    Published: 24 Aug 2023Last Modified: 26 Jun 2024

    Summary: ntpd has Dependency on Vulnerable Third-Party Component

    Details: During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki. ### Impact This vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS ### Patches Affected users are recommended to upgrade to version 0.3.7 ### References See also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md

    Affected packages

    Package

    Name: ntpd

    Purl: pkg:cargo/ntpd

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.3.7

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-37xq-q42p-rv3p | CVE-DB