{"id":"DEBIAN-CVE-2025-58066","details":"nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. In versions between 1.2.0 and 1.6.1 inclusive servers which allow non-NTS traffic are affected by a denial of service vulnerability, where an attacker can induce a message storm between two NTP servers running ntpd-rs. Client-only configurations are not affected. Affected users are recommended to upgrade to version 1.6.2 as soon as possible.","modified":"2026-09-01T20:05:54.504941604Z","published":"2025-08-29T21:15:36.280Z","upstream":["CVE-2025-58066"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-58066"}],"affected":[{"package":{"name":"rust-ntpd","ecosystem":"Debian:13","purl":"pkg:deb/debian/rust-ntpd?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.4.0-6","1.6.2-1","1.6.2-2","1.6.2-3","1.6.2-4","1.7.1-1","1.7.2-1","1.7.2-2","1.9.0-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-58066.json"}},{"package":{"name":"rust-ntpd","ecosystem":"Debian:14","purl":"pkg:deb/debian/rust-ntpd?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.2-1"}]}],"versions":["1.4.0-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-58066.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}