Stack-based buffer overflow in ntp - CVE-2017-6460

 

Stack-based buffer overflow in ntp - CVE-2017-6460

Published: May 16, 2018 / Updated: May 17, 2018


Vulnerability identifier: #VU12771
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6460
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists in the reslist() function in ntpq due to stack-based buffer overflow triggered by a malicious ntpd server when ntpq requests the restriction list from the server. A remote attacker can trigger memory corruption and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

ntp
Junos OS
Slackware Linux
Fedora
Junos OS Evolved
ntp

How to mitigate CVE-2017-6460

Update to version 4.2.8p10 or 4.3.94.

Junos OS - addressed in versions 12.3X48-D95, 12.3R12-S15, 14.1X53-D53, 15.1x49-D190, 15.1R7-S6, 16.1R7-S6, 16.2R3, 17.1R2-S11, 17.1R3-S1, 17.2R1-S9, 17.2R2-S8, 17.2R3-S3, 17.3R2-S5, 17.3R3-S6, 17.4R2-S7, 17.4R3, 18.1R3-S8, 18.2R2-S7, 18.2R3-S1, 18.3R1-S5, 18.3R2-S2, 18.3R3, 18.4R1-S4, 18.4R2-S1, 18.4R3, 19.1R1-S3, 19.1R2, 19.2R1-S1, 19.2R2, 19.3R1
ntp - update to 4.2.8p10-1.fc26
Junos OS Evolved - update to 20.1R1-EVO

External References

Related Security Bulletins