It was found that ntpq did not implement a proper lenght check when calling nextvar(), which executes a memcpy(), on the name buffer. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-7975