lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <41865692.8.614e.6585@gis.net> From: mayer at gis.net (mayer@....net) Subject: Re: ntpd segfaults accessing IPv6 hosts ----- Original Message Follows ----- > Hi full-disclosure! > > ntpd 1:4.2.0a-11 (as in debian testing/sarge and unstable/sid) > segfaults when accessing ntp servers on IPv6 hosts. I don't know > whether this bug is exploitable. But such a server on > pool.ntp.org might DoS many servers. There are no IPv6 addresses in pool.ntp.org so there is no risk here. (dig AAAA pool.ntp.org) > > There is a fixed version available. > The latest ntp-dev tarball should have the fixes. Currently the number of ntp servers with IPv6 AAAA records is very low. > For more details see http://bugzilla.ntp.org/show_bug.cgi?id=353 > > Bernhard > Danny NTP Development