Denial of service in Network Time Protocol - CVE-2018-7184

 

Denial of service in Network Time Protocol - CVE-2018-7184

Published: March 1, 2018 / Updated: March 1, 2018


Vulnerability identifier: #VU10799
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7184
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to insufficient security restrictions. A remote attacker can cause interleaved symmetric mode to crash.

Affected software

Network Time Protocol
Arch Linux
Amazon Linux AMI
Gentoo Linux
IBM AIX
FreeBSD
Slackware Linux
Fedora
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
Flex System FC3171 8Gb SAN Switch
Flex System FC3171 8Gb SAN Pass-thru
Integrated Management Module II (IMM2) for BladeCenter Systems
ntp

How to mitigate CVE-2018-7184

Update to version 4.2.8p11 or later.

System x Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Flex System Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
ntp - addressed in versions 4.2.8p11-1.fc26, 4.2.8p11-1.fc27
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.45.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.14.02.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.14.02.00

External References

Related Security Bulletins