mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be able to attack a client ntpq process, but cannot attack ntpd.
{ "binaries": [ { "binary_version": "1:4.2.6.p5+dfsg-3ubuntu2.14.04.13+esm1", "binary_name": "ntp" }, { "binary_version": "1:4.2.6.p5+dfsg-3ubuntu2.14.04.13+esm1", "binary_name": "ntpdate" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-26554.json"
{ "binaries": [ { "binary_version": "1:4.2.8p4+dfsg-3ubuntu5.10", "binary_name": "ntp" }, { "binary_version": "1:4.2.8p4+dfsg-3ubuntu5.10", "binary_name": "ntpdate" } ] }
{ "binaries": [ { "binary_version": "1:4.2.8p10+dfsg-5ubuntu7.3+esm1", "binary_name": "ntp" }, { "binary_version": "1:4.2.8p10+dfsg-5ubuntu7.3+esm1", "binary_name": "ntpdate" }, { "binary_version": "1:4.2.8p10+dfsg-5ubuntu7.3+esm1", "binary_name": "sntp" } ] }
{ "binaries": [ { "binary_version": "1:4.2.8p12+dfsg-3ubuntu4.20.04.1+esm1", "binary_name": "ntp" }, { "binary_version": "1:4.2.8p12+dfsg-3ubuntu4.20.04.1+esm1", "binary_name": "ntpdate" }, { "binary_version": "1:4.2.8p12+dfsg-3ubuntu4.20.04.1+esm1", "binary_name": "sntp" } ] }
{ "binaries": [ { "binary_version": "1:4.2.8p15+dfsg-1ubuntu2", "binary_name": "ntp" }, { "binary_version": "1:4.2.8p15+dfsg-1ubuntu2", "binary_name": "ntpdate" }, { "binary_version": "1:4.2.8p15+dfsg-1ubuntu2", "binary_name": "sntp" } ] }