I tried this to security-discuss, but I'm not sure if it went through: The Debian security team has asked me which of the February 2018 ntp-4.2.8p11 vulnerabilities apply to NTPsec: http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities -- Richard