Publish Advisories

GHSA-22gh-3r9q-xf38
GHSA-37xq-q42p-rv3p
This commit is contained in:
advisory-database[bot]
2024-06-26 15:21:35 +00:00
parent bd571269fb
commit e14aadb240
2 changed files with 3 additions and 3 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22gh-3r9q-xf38",
"modified": "2021-10-21T14:26:23Z",
"modified": "2024-06-26T15:20:26Z",
"published": "2021-09-20T19:53:30Z",
"aliases": [
"CVE-2021-39214"
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37xq-q42p-rv3p",
"modified": "2023-08-24T22:18:39Z",
"modified": "2024-06-26T15:20:09Z",
"published": "2023-08-24T22:18:39Z",
"aliases": [
],
"summary": "ntpd has Dependency on Vulnerable Third-Party Component",
"details": "### During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki.\n\n### Impact\nThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS\n\n### Patches\nAffected users are recommended to upgrade to version 0.3.7\n\n### References\nSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md\n",
"details": "During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki.\n\n### Impact\nThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS\n\n### Patches\nAffected users are recommended to upgrade to version 0.3.7\n\n### References\nSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md\n",
"severity": [
{
"type": "CVSS_V3",