CVE Database
/

CVE-2018-12327

Back to search

CVE-2018-12327

Published: Jun 20, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. NOTE: It is unclear whether there are any common situations in which ntpq or ntpdc is used with a command line from an untrusted source.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2018:3854
vendor-advisory
x_refsource_REDHAT
104517
vdb-entry
x_refsource_BID
44909
exploit
x_refsource_EXPLOIT-DB
RHSA-2018:3853
vendor-advisory
x_refsource_REDHAT
GLSA-201903-15
vendor-advisory
x_refsource_GENTOO
RHSA-2019:2077
vendor-advisory
x_refsource_REDHAT
USN-4229-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now