ntpd will crash if the server is not NTS-enabled (no certificate) and it receives an NTS-enabled client request (mode 3).
Solution:
The product does not properly determine which state it is in, causing it to assume it is in state X when in fact it is in state Y, causing it to perform incorrect operations in a security-relevant manner.
Link | Tags |
---|---|
https://gitlab.com/NTPsec/ntpsec/-/issues/794 | vendor advisory issue tracking |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038422 | third party advisory issue tracking |