NTP CVE-2018-7182 Information Disclosure Vulnerability
BID:103191
CVE-2018-7182 |Info
NTP CVE-2018-7182 Information Disclosure Vulnerability
| Bugtraq ID: | 103191 |
| Class: | Design Error |
| CVE: |
CVE-2018-7182 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2018 12:00AM |
| Updated: | Aug 15 2018 10:00AM |
| Credit: | Yihan Lian of Qihoo 360 |
| Vulnerable: |
Oracle Solaris 11.3 NTP NTP 4.2.8p9 NTP NTP 4.2.8p8 NTP NTP 4.2.8p7 NTP NTP 4.2.8p6 NTP NTP 4.2.8p10 IBM Vios 2.2.3 IBM Vios 2.2.1 4 IBM Vios 2.2 IBM Vios 2.2.4.0 IBM Vios 2.2.3.50 IBM Vios 2.2.3.4 IBM Vios 2.2.3.3 IBM Vios 2.2.3.2 IBM Vios 2.2.3.0 IBM Vios 2.2.2.6 IBM Vios 2.2.2.5 IBM Vios 2.2.2.4 IBM Vios 2.2.2.0 IBM Vios 2.2.1.3 IBM Vios 2.2.1.1 IBM Vios 2.2.1.0 IBM Vios 2.2.0.13 IBM Vios 2.2.0.12 IBM Vios 2.2.0.11 IBM Vios 2.2.0.10 IBM Aix 7.2 IBM AIX 7.1 IBM AIX 6.1 IBM AIX 5.3 |
| Not Vulnerable: |
NTP NTP 4.2.8p11 |
Discussion
NTP CVE-2018-7182 Information Disclosure Vulnerability
NTP is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
NTP is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
Exploit / POC
NTP CVE-2018-7182 Information Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NTP CVE-2018-7182 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
NTP CVE-2018-7182 Information Disclosure Vulnerability
References:
References:
- Bug 1550208 - (CVE-2018-7182) CVE-2018-7182 ntp: buffer read overrun leads infor (Redhat)
- CVE-2018-7182 (Redhat)
- NTP Homepage (ntp.org)
- NTP Bug 3412 ctl_getitem(): buffer read overrun leads to undefined behavior and (NTP)
- Oracle Solaris Third Party Bulletin - April 2018 (Oracle)
- There are multiple vulnerabilities in NTPv3 and NTPv4 that affect AIX. (IBM)