The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade ntp | May 11, 2018 | Mar 6, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 6, 2018 |
| Debian | — | Upgrade ntpsecUpgrade ntp | Jul 30, 2024 | Mar 6, 2018 |
| Freebsd | — | Upgrade ntp-develUpgrade ntpUpgrade FreeBSD | May 6, 2018 | Feb 28, 2018 |
| Gentoo Linux | — | Upgrade net-misc/ntp. | May 29, 2018 | Mar 6, 2018 |
| Hpux | — | Update NTP to the latest version | Dec 9, 2019 | Mar 6, 2018 |
| Ibm Aix | — | Apply the fix or workaround for ntp_advisory10 | Aug 16, 2018 | Mar 6, 2018 |
| Ntp | — | Upgrade to the latest version of NTP | Feb 23, 2023 | Mar 6, 2018 |
| Oracle Solaris | — | Upgrade service/network/ntp to version 4.2.8.11-0.175.3.31.0.4.0 on Solaris 11.3 | Apr 18, 2018 | Mar 6, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 6, 2018 |
| Suse | — | Upgrade ntp-docUpgrade ntp | Mar 28, 2018 | Mar 6, 2018 |
| Ubuntu | — | Upgrade ntp | Jul 13, 2018 | Mar 6, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 6, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub