Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspecified impact via a long flagstr variable in a restriction list response.
{ "binaries": [ { "binary_name": "ntp", "binary_version": "1:4.2.8p4+dfsg-3ubuntu5.5" }, { "binary_name": "ntp-dbgsym", "binary_version": "1:4.2.8p4+dfsg-3ubuntu5.5" }, { "binary_name": "ntp-doc", "binary_version": "1:4.2.8p4+dfsg-3ubuntu5.5" }, { "binary_name": "ntpdate", "binary_version": "1:4.2.8p4+dfsg-3ubuntu5.5" }, { "binary_name": "ntpdate-dbgsym", "binary_version": "1:4.2.8p4+dfsg-3ubuntu5.5" } ], "availability": "No subscription required", "ubuntu_priority": "low" }