vendor:
ntpsec
by:
Magnus Klaaborg Stubman
9.1
CVSS
CRITICAL
Out-of-bounds Read
CWE
Product Name: ntpsec
Affected Version From: 1.1.2001
Affected Version To: 1.1.2002
Patch Exists: YES
Related CWE: CVE-2019-6443
CPE:
Platforms Tested:
2019
ntpsec 1.1.2 OOB read Proof of concept
This is a proof of concept exploit for the ntpsec 1.1.2 version, which allows an out-of-bounds read vulnerability. The exploit does not crash the target.
Mitigation:
Update to a patched version of ntpsec or apply vendor-supplied patches.