Stack-based buffer overflow in Network Time Protocol - CVE-2018-12327

 

Stack-based buffer overflow in Network Time Protocol - CVE-2018-12327

Published: August 14, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU14448
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2018-12327
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The vulnerability exists due to stack-based buffer overflow in the Network Time Protocol Query (ntpq) program and Network Time Protocol daemon (ntpd) when handling malicious input. A local attacker can submit a long string argument for an IPv4 or IPv6 command-line parameter, trigger memory corruption and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Network Time Protocol
Gentoo Linux
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
IBM AIX
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for SAP HANA
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Slackware Linux
Opensuse
Fedora
ntp (Ubuntu package)
ntp (Red Hat package)
ntp
Flex System Chassis Management Module (CMM)
EMC Atmos
Data Computing Appliance (DCA)

How to mitigate CVE-2018-12327

Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.

ntp (Ubuntu package) - update to 1:4.2.8p4+dfsg-3ubuntu5.10
Flex System Chassis Management Module (CMM) - update to 2pet18a-2.5.14a
EMC Atmos - addressed in versions 2.4.2 HF504, 2.4.3 HF504
Data Computing Appliance (DCA) - update to 3.5.3.0
ntp (Red Hat package) - update to 4.2.6p5-28.el7_6.1
ntp - addressed in versions 4.2.8p12-1.fc27, 4.2.8p12-1.fc28

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins