ntp: Stack-based buffer overflow in ntpq and ntpdc allows denial of service or code execution
Published Jun 20, 2018
9.8
CRITICALCVSS 3.0
EPSS 28.02%
Description
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. NOTE: It is unclear whether there are any common situations in which ntpq or ntpdc is used with a command line from an untrusted source.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
ntp-0:4.2.6p5-15.el6_10
Fixed · RHSA-2018:3854
Red Hat Enterprise Linux 6.7 Extended Update Support
ntp-0:4.2.6p5-5.el6_7.6
Fixed · RHSA-2018:3853
Red Hat Enterprise Linux 7
ntp-0:4.2.6p5-29.el7
Fixed · RHSA-2019:2077
Red Hat Enterprise Linux 7.6 Extended Update Support
ntp-0:4.2.6p5-28.el7_6.1
Fixed · RHSA-2020:1470
Red Hat Enterprise Linux 5
ntp
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | ntp-0:4.2.6p5-15.el6_10 | Fixed | RHSA-2018:3854 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | ntp-0:4.2.6p5-5.el6_7.6 | Fixed | RHSA-2018:3853 |
| Red Hat Enterprise Linux 7 | ntp-0:4.2.6p5-29.el7 | Fixed | RHSA-2019:2077 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | ntp-0:4.2.6p5-28.el7_6.1 | Fixed | RHSA-2020:1470 |
| Red Hat Enterprise Linux 5 | ntp | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of ntp as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having a security impact of Low. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. This issue affects the versions of ntp as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
References (14)
- http://www.securityfocus.com/bid/104517 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:3853 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2018:3854 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2077 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2018-12327 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1593580 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-4301 Advisory
- https://gist.github.com/fakhrizulkifli/9b58ed8e0354e8deee50b0eebd1c011f x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-12327
- https://security.gentoo.org/glsa/201903-15 vendor-advisoryx_refsource_GENTOO
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us x_refsource_CONFIRM
- https://usn.ubuntu.com/4229-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2018-12327
- https://www.exploit-db.com/exploits/44909/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.