CVE-2018-7184
06.03.2018, 20:29
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ntp | ntp | 4.2.8:p10 |
| ntp | ntp | 4.2.8:p4 |
| ntp | ntp | 4.2.8:p5 |
| ntp | ntp | 4.2.8:p6 |
| ntp | ntp | 4.2.8:p7 |
| ntp | ntp | 4.2.8:p8 |
| ntp | ntp | 4.2.8:p9 |
| synology | router_manager | 1.1 |
| synology | skynas | - |
| synology | virtual_diskstation_manager | - |
| synology | diskstation_manager | 5.2 |
| synology | diskstation_manager | 6.0 |
| synology | diskstation_manager | 6.1 |
| synology | vs960hd_firmware | - |
| slackware | slackware_linux | 14.0 |
| slackware | slackware_linux | 14.1 |
| slackware | slackware_linux | 14.2 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 17.10 |
| canonical | ubuntu_linux | 18.04 |
| netapp | cloud_backup | - |
| netapp | steelstore_cloud_integrated_storage | - |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References