ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation. https://nvd.nist.gov/vuln/detail/CVE-2015-5195
configure a project with "template=feature/ntp428p10" then build ntp you will find the new build ntp is not V-4.2.8p10.