PT-2018-2211 · Ntp+5 · Ntp+5

Yihan Lian

·

Published

2018-03-04

·

Updated

2024-06-15

·

CVE-2018-7182

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ntp versions 4.2.8p6 through 4.2.8p10
Description The issue is related to the ctl getitem method in ntpd, which is part of the NTP protocol implementation. It involves a buffer read beyond its boundaries in memory. This can be exploited by a remote attacker using specially crafted mode 6 packets, potentially leading to a denial of service. Additionally, there's a concern about the failure to prevent Sybil attacks from authenticated peers, which could allow an attacker to bypass security restrictions and modify a victim's clock by creating multiple ephemeral associations.
Recommendations For versions 4.2.8p6 through 4.2.8p10, update to version 4.2.8p11 or later to resolve the issue. As a temporary workaround, consider restricting access to mode 6 packets to minimize the risk of exploitation. Restrict the ability to create multiple ephemeral associations to prevent Sybil attacks.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1361
BDU:2019-00219
CVE-2018-7182
MGASA-2018-0195
OPENSUSE-SU-2024:11102-1
OPENSUSE-SU-2024:11103-1
SUSE-SU-2018:0808-1
SUSE-SU-2018:0956-1
SUSE-SU-2018:1464-1
SUSE-SU-2018:1765-1
SUSE-SU-2018:1765-2
SUSE-SU-2018_0808-1
SUSE-SU-2018_0956-1
SUSE-SU-2018_1464-1
SUSE-SU-2018_1765-1
SUSE-SU-2018_1765-2
USN-3707-1

Affected Products

Alt Linux
Freebsd
Ibm Aix
Suse
Ubuntu
Ntp