ZeroHour

CVE-2018-7184

CVSS 3.0
7.5 high
EPSS
9%p95
Published
()
Modified
Description

ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.

Vendors
ntpsynologyslackwarecanonicalnetapp
Products
ntp, router manager, skynas, virtual diskstation manager, diskstation manager, vs960hd firmware, slackware linux, ubuntu linux, cloud backup, steelstore cloud integrated storage
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.