Stack-based buffer overflow in Network Time Protocol - CVE-2018-12327
Published: August 14, 2018 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The vulnerability exists due to stack-based buffer overflow in the Network Time Protocol Query (ntpq) program and Network Time Protocol daemon (ntpd) when handling malicious input. A local attacker can submit a long string argument for an IPv4 or IPv6 command-line parameter, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
IBM AIX
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for SAP HANA
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Slackware Linux
Opensuse
Fedora
ntp (Ubuntu package)
ntp (Red Hat package)
ntp
Flex System Chassis Management Module (CMM)
EMC Atmos
Data Computing Appliance (DCA)
How to mitigate CVE-2018-12327
Flex System Chassis Management Module (CMM) - update to 2pet18a-2.5.14a
EMC Atmos - addressed in versions 2.4.2 HF504, 2.4.3 HF504
Data Computing Appliance (DCA) - update to 3.5.3.0
ntp (Red Hat package) - update to 4.2.6p5-28.el7_6.1
ntp - addressed in versions 4.2.8p12-1.fc27, 4.2.8p12-1.fc28
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Privilege escalation in Network Time Protocol
- Slackware Linux update for ntp
- Amazon Linux AMI update for ntp
- Arch Linux update for ntp
- OpenSUSE Linux update for ntp
- Multiple vulnerabilities in IBM AIX
- Red Hat update for ntp
- Red Hat update for ntp
- Arch Linux update for ntp
- Red Hat update for ntp
- Gentoo update for NTP
- Ubuntu update for NTP
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in Dell EMC Atmos
- Red Hat Enterprise Linux 7.6 Extended Update Support update for ntp
- IBM Flex System Chassis Management Module (CMM) update for NTP
- Fedora 27 update for ntp
- Fedora 28 update for ntp