{"id":"CVE-2016-5117","details":"OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass the man-in-the-middle mitigations via a crafted timestamp constraint with a valid certificate.","modified":"2026-03-14T14:16:00.133303Z","published":"2017-01-31T19:59:00.230Z","references":[{"type":"ADVISORY","url":"http://www.openntpd.org/txt/release-6.0p1.txt"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/05/23/2"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/05/29/6"},{"type":"FIX","url":"http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.sbin/ntpd/constraint.c.diff?r1=1.27&r2=1.28"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5117.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"6.0"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}