← Vulnerability feed

Vulnerability record · CVE-2019-6442 · published 16 January 2019

CVE-2019-6442: Ntpsec out-of-bounds write vulnerability

Ntpsec · Ntpsec

An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y.

6.5 CVSS 3.0 Medium EPSS 14% · top 3.6% CWE-787 · Out-of-bounds write
6.5CVSS 3.0 base score, v2 4.0
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://dumpco.re/blog/ntpsec-bugs ExploitThird Party Advisory
https://dumpco.re/bugs/ntpsec-authed-oobwrite ExploitThird Party Advisory
https://github.com/ntpsec/ntpsec/blob/NTPsec_1_1_3/NEWS Release NotesThird Party Advisory
https://www.exploit-db.com/exploits/46178/ ExploitThird Party AdvisoryVDB Entry
https://dumpco.re/blog/ntpsec-bugs ExploitThird Party Advisory
https://dumpco.re/bugs/ntpsec-authed-oobwrite ExploitThird Party Advisory
https://github.com/ntpsec/ntpsec/blob/NTPsec_1_1_3/NEWS Release NotesThird Party Advisory
https://www.exploit-db.com/exploits/46178/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2019-6442 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2019-6443NTPsec ntpd stack buffer over-read via ctl_getitem in read_sysvarsNTPsec before 1.1.3 contains a bug in ctl_getitem that causes a stack-based buffer over-read in read_sysvars in ntp_control.c within ntpd. The flaw i…EPSS 67%analysed9.1CVE-2019-6444NTPsec ntpd control packet stack buffer over-readNTPsec before 1.1.3 has a stack-based buffer over-read in process_control() in ntp_control.c, where attacker-controlled data is dereferenced by ntohl…EPSS 46%analysed7.5CVE-2023-4012Ntpsec vulnerabilityntpd will crash if the server is not NTS-enabled (no certificate) and it receives an NTS-enabled client request (mode 3).EPSS 0.45%7.4CVE-2021-22212Ntpsec broken cryptographic algorithm vulnerabilityntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters. ntpd then either pads, shor…EPSS 0.52%6.5CVE-2019-6445Ntpsec null pointer dereference vulnerabilityAn issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, relat…EPSS 14%3.7CVE-2016-1551Ntp vulnerabilityntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that im…EPSS 2.2%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed

Source: NIST National Vulnerability Database (record CVE-2019-6442), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.