CVE-2018-7183

Publication date 8 March 2018

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Description

Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.

Status

Package Ubuntu Release Status
ntp 18.10 cosmic
Fixed 1:4.2.8p11+dfsg-1ubuntu1
18.04 LTS bionic
Fixed 1:4.2.8p10+dfsg-5ubuntu7.1
17.10 artful
Fixed 1:4.2.8p10+dfsg-5ubuntu3.3
16.04 LTS xenial
Fixed 1:4.2.8p4+dfsg-3ubuntu5.9
14.04 LTS trusty
Fixed 1:4.2.6.p5+dfsg-3ubuntu2.14.04.13

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
ntp

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.8 · Critical

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Access our resources on patching vulnerabilities