Improper input validation in Network Time Protocol - CVE-2018-7185

 

Improper input validation in Network Time Protocol - CVE-2018-7185

Published: March 1, 2018 / Updated: March 1, 2018


Vulnerability identifier: #VU10803
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7185
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.

The weakness exists due to insufficient validation of user-supplied input. A remote attacker can submit continuous crafted packets and cause the service to crash.

Affected software

Network Time Protocol
Arch Linux
Amazon Linux AMI
Gentoo Linux
IBM AIX
FreeBSD
Slackware Linux
Fedora
System x Integrated Management Module (IMM2)
Flex System Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
Flex System FC3171 8Gb SAN Switch
Flex System FC3171 8Gb SAN Pass-thru
Integrated Management Module II (IMM2) for BladeCenter Systems
ntp

How to mitigate CVE-2018-7185

Update to version ntp-4.2.8p11 or later.

System x Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Flex System Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
ntp - addressed in versions 4.2.8p11-1.fc26, 4.2.8p11-1.fc27
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.45.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.14.02.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.14.02.00

External References

Related Security Bulletins