The ntpd(8) daemon is prone to a stack-based buffer-overflow vulnerability when it is used to use the “autokey” security model. The issue could be exploited to execute arbitrary code in the context of the service daemon, or crash the service. The vulnerability has been verified to apply to all supported versions of Freebses 6.3, 6.4, 7.1, and 7.2 systems. Use the relevant patch from the location below, and verify the PGP signature.”]
Source: https://taosecurity.blogspot.com/2009/09/open-source-vulnerability-disclosure.html