CVE-2017-6462 (retired)

Priority
Description
Buffer overflow in the legacy Datum Programmable Time Server (DPTS)
refclock driver in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local
users to have unspecified impact via a crafted /dev/datum device.
Package
Source: ntp (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):released (1:4.2.6.p3+dfsg-1ubuntu3.12)
Ubuntu 14.04 LTS (Trusty Tahr):released (1:4.2.6.p5+dfsg-3ubuntu2.14.04.11)
Ubuntu 16.04 LTS (Xenial Xerus):released (1:4.2.8p4+dfsg-3ubuntu5.5)
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (1:4.2.8p10+dfsg-5ubuntu1)
Ubuntu 18.10 (Cosmic Cuttlefish):not-affected (1:4.2.8p10+dfsg-5ubuntu1)
Ubuntu 19.04 (Disco Dingo):not-affected (1:4.2.8p10+dfsg-5ubuntu1)
Patches:
Upstream:http://bk1.ntp.org/ntp-stable/?PAGE=cset&REV=58a0592bal7oYBqUMCqId4WgiuiOqw
More Information

Updated: 2019-03-26 12:26:14 UTC (commit ccdecfcf0fead22bd291e5f4ea745a46872dcb15)