NTP CVE-2018-7183 Buffer Overflow Vulnerability
BID:103351
CVE-2018-7183 |Info
NTP CVE-2018-7183 Buffer Overflow Vulnerability
| Bugtraq ID: | 103351 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2018-7183 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2018 12:00AM |
| Updated: | Aug 15 2018 10:00AM |
| Credit: | Michael Macnair of Thales e-Security. |
| Vulnerable: |
Oracle Solaris 11.3 NTP NTP 4.2.8p9 NTP NTP 4.2.8p8 NTP NTP 4.2.8p7 NTP NTP 4.2.8p6 NTP NTP 4.2.8p10 IBM Vios 2.2.3 IBM Vios 2.2.1 4 IBM Vios 2.2 IBM Vios 2.2.4.0 IBM Vios 2.2.3.50 IBM Vios 2.2.3.4 IBM Vios 2.2.3.3 IBM Vios 2.2.3.2 IBM Vios 2.2.3.0 IBM Vios 2.2.2.6 IBM Vios 2.2.2.5 IBM Vios 2.2.2.4 IBM Vios 2.2.2.0 IBM Vios 2.2.1.3 IBM Vios 2.2.1.1 IBM Vios 2.2.1.0 IBM Vios 2.2.0.13 IBM Vios 2.2.0.12 IBM Vios 2.2.0.11 IBM Vios 2.2.0.10 IBM Aix 7.2 IBM AIX 7.1 IBM AIX 6.1 IBM AIX 5.3 FreeBSD Freebsd 11.1 FreeBSD Freebsd 10.4-RELEASE-p3 FreeBSD Freebsd 10.4 FreeBSD Freebsd 10.3-RELEASE-p5 FreeBSD Freebsd 10.3-RELEASE-p4 FreeBSD Freebsd 10.3-RELEASE-p3 FreeBSD Freebsd 10.3-RELEASE-p24 FreeBSD Freebsd 10.3-RELEASE-p20 FreeBSD Freebsd 10.3-RELEASE-p2 FreeBSD Freebsd 10.3-RELEASE-p19 FreeBSD Freebsd 10.3-RELEASE-p15 FreeBSD Freebsd 10.3-RELEASE-p13 FreeBSD Freebsd 10.3-RELEASE-p1 FreeBSD Freebsd 10.3 |
| Not Vulnerable: |
NTP NTP 4.2.8p11 FreeBSD Freebsd 11.1-STABLE FreeBSD Freebsd 11.1-RELEASE-p7 FreeBSD Freebsd 10.4-STABLE FreeBSD Freebsd 10.4-RELEASE-p6 FreeBSD Freebsd 10.3-RELEASE-p27 |
Discussion
NTP CVE-2018-7183 Buffer Overflow Vulnerability
NTP is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
NTP versions 4.2.8p6 through 4.2.8p10 are vulnerable.
NTP is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
NTP versions 4.2.8p6 through 4.2.8p10 are vulnerable.
Exploit / POC
NTP CVE-2018-7183 Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NTP CVE-2018-7183 Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
NTP CVE-2018-7183 Buffer Overflow Vulnerability
References:
References:
- Bug 1550223 - (CVE-2018-7183) CVE-2018-7183 ntp: decodearr() can write beyond it (Red Hat Bugzilla)
- CVE-2018-7183 (Red Hat Bugzilla)
- NTP Homepage (ntp.org)
- February 2018 ntp-4.2.8p11 NTP Security Vulnerability Announcement (NTP)
- ntpq: decodearr() can write beyond its 'buf' limits (NTP)
- Oracle Solaris Third Party Bulletin - April 2018 (Oracle)
- There are multiple vulnerabilities in NTPv3 and NTPv4 that affect AIX. (IBM)