PT-2018-2021 · Ntp+5 · Ntp+5

Miroslav Lichvar

·

Published

2018-03-04

·

Updated

2025-01-14

·

CVE-2018-7185

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ntp versions 4.2.6 through 4.2.8p10
Description The issue is related to the implementation of the NTP protocol, specifically with insufficient input validation. This can be exploited by a remote attacker to cause a denial of service by sending specially crafted packets. The protocol engine in ntp allows a remote attacker to disrupt the service by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association, causing the victim ntpd to reset its association. Additionally, the failure to prevent Sybil attacks from authenticated peers can allow an attacker to bypass security restrictions and modify a victim's clock by creating multiple ephemeral associations.
Recommendations For ntp versions 4.2.6 through 4.2.8p10, update to version 4.2.8p11 or later to resolve the issue. As a temporary workaround, consider restricting access to the ntp service to minimize the risk of exploitation. Avoid using the ntp service until the issue is resolved.

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1361
BDU:2018-01637
CVE-2018-7185
MGASA-2018-0195
OPENSUSE-SU-2024:11102-1
SUSE-SU-2018:0808-1
SUSE-SU-2018:0956-1
SUSE-SU-2018:1464-1
SUSE-SU-2018:1765-1
SUSE-SU-2018:1765-2
USN-3707-1
USN-3707-2

Affected Products

Alt Linux
Freebsd
Ibm Aix
Suse
Ubuntu
Ntp