CVE-2017-6460: Ntp

High severity, CVSS 8.8. EPSS: 2.7% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspecified impact via a long flagstr variable in a restriction list response.

Affected products

  • Ntp Ntp: version 4.2.8 only; version 4.3.0 only; version 4.3.1 only; version 4.3.2 only; version 4.3.3 only; version 4.3.4 only; …

Published 2017-03-27. Last modified 2026-06-17.