Vulnerability Description
Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ntp | Ntp | 4.2.8 |
| Freebsd | Freebsd | 10.3 |
| Canonical | Ubuntu Linux | 12.04 |
| Netapp | Element Software | - |
Related Weaknesses (CWE)
References
- http://support.ntp.org/bin/view/Main/NtpBug3414Vendor Advisory
- http://support.ntp.org/bin/view/Main/SecurityNotice#February_2018_ntp_4_2_8p11_NVendor Advisory
- http://www.securityfocus.com/bid/103351Third Party AdvisoryVDB Entry
- https://security.FreeBSD.org/advisories/FreeBSD-SA-18:02.ntp.ascThird Party Advisory
- https://security.gentoo.org/glsa/201805-12Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180626-0001/Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpe
- https://usn.ubuntu.com/3707-1/Third Party Advisory
- https://usn.ubuntu.com/3707-2/Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html
- https://www.synology.com/support/security/Synology_SA_18_13Third Party Advisory
- http://support.ntp.org/bin/view/Main/NtpBug3414Vendor Advisory
- http://support.ntp.org/bin/view/Main/SecurityNotice#February_2018_ntp_4_2_8p11_NVendor Advisory
- http://www.securityfocus.com/bid/103351Third Party AdvisoryVDB Entry
- https://security.FreeBSD.org/advisories/FreeBSD-SA-18:02.ntp.ascThird Party Advisory
FAQ
What is CVE-2018-7183?
CVE-2018-7183 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted ar...
How severe is CVE-2018-7183?
CVE-2018-7183 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-7183?
Check the references section above for vendor advisories and patch information. Affected products include: Ntp Ntp, Freebsd Freebsd, Canonical Ubuntu Linux, Netapp Element Software.