Database/Control plane, storage & DevOps
ntpq / ntpdc (NTP 4.2.8p11 client utilities): Stack buffer overflow in the ntpq and ntpdc command-line tools via a long
Impact
Stack buffer overflow in the ntpq and ntpdc command-line tools via a long argument, giving code execution or privilege escalation. The interesting case for a cluster operator is automation: monitoring scripts that shell out to ntpq with a hostname taken from inventory turn an inventory-poisoning bug into code execution on the monitoring host.
Who can reach it
Local, via a long argument to ntpq/ntpdc — reachable wherever these tools are invoked with externally influenced arguments.
What to do
Upgrade the ntp package. No service restart needed for the client tools; nothing to reboot. Audit any monitoring or automation that passes untrusted strings to ntpq.
References
Related entries
- Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api): rbd-target-api ships with the Werkzeug debug console enabledCVE-2018-14649 · Ceph iSCSI gateway (ceph-iscsi-cli / rbd-target-api)Critical
- Raritan CommandCenter Secure Gateway (CC-SG), before 8.0.0: CC-SG is Raritan's single-pane-of-glass gateway thatCVE-2018-20687 · Raritan CommandCenter Secure Gateway (CC-SG), before 8.0.0Critical
- Slurm (slurmdbd accounting database daemon): SQL injection into SlurmDBD gives an attacker read and write control ofCVE-2018-7033 · Slurm (slurmdbd accounting database daemon)Critical
- Kemp LoadMaster (LMOS): A flaw in session management lets a remote, unauthenticated attacker bypass the LoadMaster'sCVE-2018-9091 · Kemp LoadMaster (LMOS)Critical
- Slurm (slurmdbd, sacctmgr archive load): A second SQL injection path into SlurmDBD, this one through the 'sacctmgrCVE-2019-12838 · Slurm (slurmdbd, sacctmgr archive load)Critical
- HTCondor (condor_startd, condor_schedd, condor_shadow): One CVE covering four separate authentication failures theCVE-2019-18823 · HTCondor (condor_startd, condor_schedd, condor_shadow)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.