Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.
2018-03-08T20:29:00.423
2024-11-21T04:11:44.593
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ntp | ntp | 4.2.8 | Yes |
Application | ntp | ntp | 4.2.8 | Yes |
Application | ntp | ntp | 4.2.8 | Yes |
Application | ntp | ntp | 4.2.8 | Yes |
Application | ntp | ntp | 4.2.8 | Yes |
Operating System | freebsd | freebsd | 10.3 | Yes |
Operating System | freebsd | freebsd | 10.4 | Yes |
Operating System | freebsd | freebsd | 11.1 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 17.10 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Application | netapp | element_software | - | Yes |