mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
{ "binaries": [ { "binary_name": "ntp", "binary_version": "1:4.2.6.p5+dfsg-3ubuntu2.14.04.13+esm1" }, { "binary_name": "ntpdate", "binary_version": "1:4.2.6.p5+dfsg-3ubuntu2.14.04.13+esm1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-26552.json"
{ "binaries": [ { "binary_name": "ntp", "binary_version": "1:4.2.8p4+dfsg-3ubuntu5.10" }, { "binary_name": "ntpdate", "binary_version": "1:4.2.8p4+dfsg-3ubuntu5.10" } ] }
{ "binaries": [ { "binary_name": "ntp", "binary_version": "1:4.2.8p10+dfsg-5ubuntu7.3+esm1" }, { "binary_name": "ntpdate", "binary_version": "1:4.2.8p10+dfsg-5ubuntu7.3+esm1" }, { "binary_name": "sntp", "binary_version": "1:4.2.8p10+dfsg-5ubuntu7.3+esm1" } ] }
{ "binaries": [ { "binary_name": "ntp", "binary_version": "1:4.2.8p12+dfsg-3ubuntu4.20.04.1+esm1" }, { "binary_name": "ntpdate", "binary_version": "1:4.2.8p12+dfsg-3ubuntu4.20.04.1+esm1" }, { "binary_name": "sntp", "binary_version": "1:4.2.8p12+dfsg-3ubuntu4.20.04.1+esm1" } ] }
{ "binaries": [ { "binary_name": "ntp", "binary_version": "1:4.2.8p15+dfsg-1ubuntu2" }, { "binary_name": "ntpdate", "binary_version": "1:4.2.8p15+dfsg-1ubuntu2" }, { "binary_name": "sntp", "binary_version": "1:4.2.8p15+dfsg-1ubuntu2" } ] }