The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | amazon-linux-upgrade-ntp | May 11, 2018 | Mar 6, 2018 |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Mar 6, 2018 | |
| Debian | debian-upgrade-ntpdebian-upgrade-ntpsec | Jul 30, 2024 | Mar 6, 2018 | |
| Freebsd | freebsd-upgrade-base-11_1-release-p7freebsd-upgrade-base-10_4-release-p6freebsd-upgrade-base-10_3-release-p27freebsd-upgrade-package-ntpfreebsd-upgrade-package-ntp-devel | May 6, 2018 | Feb 28, 2018 | |
| Gentoo Linux | gentoo-linux-upgrade-net-misc-ntp | May 29, 2018 | Mar 6, 2018 | |
| Hpux | — | hpux-update-ntp | Dec 9, 2019 | Mar 6, 2018 |
| Ibm Aix | ibm-aix-ntp_advisory10 | Aug 16, 2018 | Mar 6, 2018 | |
| Ntp | ntp-upgrade-latest | Feb 23, 2023 | Mar 6, 2018 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-service-network-ntp-4-2-8-11-0-175-3-31-0-4-0 | Apr 18, 2018 | Mar 6, 2018 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Mar 6, 2018 |
| Suse | — | suse-upgrade-ntpsuse-upgrade-ntp-doc | Mar 28, 2018 | Mar 6, 2018 |
| Ubuntu | ubuntu-upgrade-ntp | Jul 13, 2018 | Mar 6, 2018 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Mar 6, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub