← All CVEs

CVE-2016-2518

medium · 5.3

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.

5.3
CVSS
15.1%
EPSS (exploit prob.)
97th
EPSS percentile
2017-01-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
ntpntp< 4.2.8
ntpntp>= 4.3.0, < 4.3.92
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
debiandebian_linux8.0
debiandebian_linux9.0
debiandebian_linux10.0
netappclustered_data_ontapall versions
netappdata_ontapall versions
netapponcommand_balanceall versions
netapponcommand_performance_managerall versions
netapponcommand_unified_manager_for_clustered_data_ontapall versions
oraclecommunications_user_data_repository10.0.0
oraclecommunications_user_data_repository10.0.1
oraclecommunications_user_data_repository12.0.0
oraclelinux6
oraclelinux7
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-2518