CVE-2019-6442: Ntpsec

Medium severity, CVSS 6.5. EPSS: 13.7% chance of exploitation in the next 30 days.

An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y.

Affected products

  • Ntpsec Ntpsec: before 1.1.3 (fixed in 1.1.3)

Published 2019-01-16. Last modified 2026-06-17.