CVE-2018-7183

CRITICAL

ntp 4.2.8p6-4.2.8p10 - Remote Code Execution via Crafted ntpq Response Array

Title source: llm
STIX 2.1

Description

Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.

References (11)

Core 11
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201805-12
Third Party Advisory vendor-advisory x_refsource_freebsd
https://security.FreeBSD.org/advisories/FreeBSD-SA-18:02.ntp.asc
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3707-2/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3707-1/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103351
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180626-0001/
Third Party Advisory x_refsource_confirm
https://www.synology.com/support/security/Synology_SA_18_13
Vendor Advisory x_refsource_confirm
http://support.ntp.org/bin/view/Main/NtpBug3414

Scores

CVSS v3 9.8
EPSS 0.3204
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (10)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 17.10
canonical/ubuntu_linux 18.04
freebsd/freebsd 10.3
freebsd/freebsd 10.4
freebsd/freebsd 11.1
netapp/element_software
ntp/ntp 4.2.8 p10 (5 CPE variants)
Published Mar 08, 2018
Tracked Since Feb 18, 2026