vendor:
ntp
by:
Magnus Klaaborg Stubman
7.5
CVSS
HIGH
Out-of-Bounds Read
Unknown
CWE
Product Name: ntp
Affected Version From: ntp 4.2.8p6
Affected Version To: ntp 4.2.8p10
Patch Exists: NO
Related CWE: CVE-2018-7182
CPE: Unknown
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2018-7182/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2018-7182/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2018-7182/, https://www.rapid7.com/db/vulnerabilities/ibm-aix-cve-2018-7182/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2018-7182/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2018-7182/, https://www.rapid7.com/db/vulnerabilities/ntp-cve-2018-7182/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2018-7182/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2018-7182/
Platforms Tested:
2018
ntpd 4.2.8p10 – Out-of-Bounds Read (PoC)
This is a proof-of-concept exploit that crashes the target when the target is run under a memory sanitiser such as ASan / Valgrind.
Mitigation:
Unknown