GPU VulnDB

Database/Control plane, storage & DevOps

ntpq / ntpdc (NTP 4.2.8p11 client utilities): Stack buffer overflow in the ntpq and ntpdc command-line tools via a long

CVE-2018-12327Control plane, storage & DevOpscurated

Impact

Stack buffer overflow in the ntpq and ntpdc command-line tools via a long argument, giving code execution or privilege escalation. The interesting case for a cluster operator is automation: monitoring scripts that shell out to ntpq with a hostname taken from inventory turn an inventory-poisoning bug into code execution on the monitoring host.

Who can reach it

Local, via a long argument to ntpq/ntpdc — reachable wherever these tools are invoked with externally influenced arguments.

What to do

Upgrade the ntp package. No service restart needed for the client tools; nothing to reboot. Audit any monitoring or automation that passes untrusted strings to ntpq.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.