Memory corruption in Network Time Protocol - CVE-2018-7183
Published: March 1, 2018 / Updated: March 1, 2018
Vulnerability identifier: #VU10802
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7183
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to execute arbitrary code on the target system.
The weakness exists in the decodearr() function of the ntpq monitoring and control program for ntpd used by the Network Time Protocol due to boundary error while attempting to decode an array in a response string when formatted data is being displayed. A remote attacker who is able to read an ntpq request while the request is being transmitted to a remote ntpd server can forge and send a specially crafted response to the targeted system prior to the remote ntpd server sending its response, trigger out-of-bounds write in the decodearr() function and inject and execute arbitrary code.
The weakness exists in the decodearr() function of the ntpq monitoring and control program for ntpd used by the Network Time Protocol due to boundary error while attempting to decode an array in a response string when formatted data is being displayed. A remote attacker who is able to read an ntpq request while the request is being transmitted to a remote ntpd server can forge and send a specially crafted response to the targeted system prior to the remote ntpd server sending its response, trigger out-of-bounds write in the decodearr() function and inject and execute arbitrary code.
Affected software
Network Time Protocol
Arch Linux
Amazon Linux AMI
Gentoo Linux
IBM AIX
FreeBSD
Fedora
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
Flex System FC3171 8Gb SAN Switch
Flex System FC3171 8Gb SAN Pass-thru
Integrated Management Module II (IMM2) for BladeCenter Systems
ntp
Arch Linux
Amazon Linux AMI
Gentoo Linux
IBM AIX
FreeBSD
Fedora
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
Flex System FC3171 8Gb SAN Switch
Flex System FC3171 8Gb SAN Pass-thru
Integrated Management Module II (IMM2) for BladeCenter Systems
ntp
How to mitigate CVE-2018-7183
Update to version 4.2.8p11.
System x Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Flex System Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
ntp - addressed in versions 4.2.8p11-1.fc26, 4.2.8p11-1.fc27
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.45.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.14.02.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.14.02.00
Flex System Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
ntp - addressed in versions 4.2.8p11-1.fc26, 4.2.8p11-1.fc27
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.45.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.14.02.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.14.02.00
External References
Related Security Bulletins
- Multiple vulnerabilities in Network Time Protocol
- FreeBSD update for ntpd
- Arch Linux update for ntp
- Amazon Linux AMI update for ntp
- Gentoo update for NTP
- Multiple vulnerabilities in IBM AIX
- Multiple vulnerabilities in QLogic 8Gb Intelligent Pass-thru Module and SAN Switch Module for IBM BladeCenter and IBM Flex System FC3171 8Gb SAN Switch & SAN Pass-thru
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Multiple vulnerabilities in IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter Systems
- Fedora 27 update for ntp
- Fedora 26 update for ntp