GHSA-2xpx-vcmq-5f72
HIGHCVE-2024-38528Missing limit for accepted NTS-KE connections allows an unauthenticated remote attacker to crash ntpd-rs when an NTS-KE server is configured. Non NTS-KE server configurations, such as the default ntpd-rs configuration, are unaffected.
- Affected
- >= 0.3.1, <= 1.1.2
- Fixed in
- 1.1.3
- Weakness
- CWE-770
- Published
- 2024-06-28
- Source
- github