LOW2.6
GHSA-37xq-q42p-rv3p
ntpd has Dependency on Vulnerable Third-Party Component
Details
During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki.
### Impact This vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS
### Patches Affected users are recommended to upgrade to version 0.3.7
### References See also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/pendulum-project/ntpd-rs/security/advisories/GHSA-37xq-q42p-rv3p[WEB]
- https://github.com/pendulum-project/ntpd-rs/commit/927952a440176a18f3ded132eb831ae7f7ac5c00[WEB]
- https://github.com/pendulum-project/ntpd-rs[PACKAGE]
- https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md[WEB]