Back to search
CVE-2018-12327
Published: Jun 20, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. NOTE: It is unclear whether there are any common situations in which ntpq or ntpdc is used with a command line from an untrusted source.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2018:3854
vendor-advisory
x_refsource_REDHAT
104517
vdb-entry
x_refsource_BID
44909
exploit
x_refsource_EXPLOIT-DB
RHSA-2018:3853
vendor-advisory
x_refsource_REDHAT
GLSA-201903-15
vendor-advisory
x_refsource_GENTOO
RHSA-2019:2077
vendor-advisory
x_refsource_REDHAT
USN-4229-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now