{"id":"GHSA-v83q-83hj-rw38","aliases":[],"url":"https://o3.security/vulnerability/GHSA-v83q-83hj-rw38","summary":"ntpd NTS client denial of service via wrongly sized cookies","details":"Two denial of service vulnerabilities were found in ntpd-rs related to the handling of NTS cookies in our client functionality. Whenever an NTS source is configured and the server behind that source is sending zero-sized cookies or cookies larger than what would fit in our buffer size, ntpd-rs would crash. Only configured NTS sources can abuse these vulnerabilities. NTP sources or third parties that are not configured cannot make use of these vulnerabilities.\n\nFor zero-sized cookies: a division by zero would force an exit when the number of new cookies that would need to be requested is calculated. In ntpd-rs 1.5.0 a check was added to prevent the division by zero.\n\nFor large cookies: while trying to send a NTP request with the cookie included, the buffer is too small to handle the cookie and an exit of ntpd-rs is forced once a write to the buffer is attempted. The memory outside the buffer would not be written to in this case. In ntpd-rs 1.5.0 a check was added that prevents accepting cookies larger than 350 bytes.\n\nUsers of older versions of ntpd-rs are recommended to update to the latest version. If an update is impossible, it is recommended to only add NTS sources to ntpd-rs that are trusted to not abuse this bug.","published":"2025-02-28T17:46:36Z","modified":"2025-02-28T17:46:36Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"ntpd","fixedVersion":"1.5.0"}],"fix":{"url":"https://github.com/pendulum-project/ntpd-rs/commit/10a103b471dae25ac598140df0c195b6531bf716","label":"pendulum-project/ntpd-rs@10a103b"},"references":[{"type":"WEB","url":"https://github.com/pendulum-project/ntpd-rs/security/advisories/GHSA-v83q-83hj-rw38"},{"type":"WEB","url":"https://github.com/pendulum-project/ntpd-rs/commit/10a103b471dae25ac598140df0c195b6531bf716"},{"type":"WEB","url":"https://github.com/pendulum-project/ntpd-rs/commit/37dd8d9a0faa03e7dfe3a4bf64953010f075c3e2"},{"type":"PACKAGE","url":"https://github.com/pendulum-project/ntpd-rs"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-28T17:46:36Z"}}