NTP BUG 3380: Off-by-one in Oncore GPS Receiver

Last update: April 22, 2024 18:49 UTC (7e7bd5857)


Summary

Resolved 4.2.8p10 21 Mar 2017
References Bug 3380
Affects All versions of NTP, up to but not including ntp-4.2.8p10,
and ntp-4.3.0 up to, but not including ntp-4.3.94.
Resolved in 4.2.8p10.
CVSS2 Score NONE 0.0 AV:L/AC:H/Au:N/C:N/I:N/A:N
CVSS3 Score NONE 0.0 CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:N

Description

There is a fencepost error in a “recovery branch” of the code for the Oncore GPS receiver if the communication link to the ONCORE is weak / distorted and the decoding doesn’t work.


Mitigation


Credit

This weakness was discovered by Cure53.


Timeline