← All CVEs

CVE-2018-7183

critical · 9.8

Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.

9.8
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2018-03-08
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
ntpntp4.2.8
freebsdfreebsd10.3
freebsdfreebsd10.4
freebsdfreebsd11.1
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux17.10
canonicalubuntu_linux18.04
netappelement_softwareall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-7183