NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."
The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.