7.5

CVE-2018-7184

ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ntp ≫ Ntp Version 4.2.8 Update p10
Ntp ≫ Ntp Version 4.2.8 Update p4
Ntp ≫ Ntp Version 4.2.8 Update p5
Ntp ≫ Ntp Version 4.2.8 Update p6
Ntp ≫ Ntp Version 4.2.8 Update p7
Ntp ≫ Ntp Version 4.2.8 Update p8
Ntp ≫ Ntp Version 4.2.8 Update p9
Synology ≫ Router Manager Version 1.1
Synology ≫ Skynas Version -
Synology ≫ Diskstation Manager Version 5.2
Synology ≫ Diskstation Manager Version 6.0
Synology ≫ Diskstation Manager Version 6.1
Synology ≫ Vs960hd Firmware Version -
Slackware ≫ Slackware Linux Version 14.0
Slackware ≫ Slackware Linux Version 14.1
Slackware ≫ Slackware Linux Version 14.2
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.10
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Netapp ≫ Cloud Backup Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.53% 0.946
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_us
https://www.synology.com/support/security/Synology_SA_18_13
Third Party Advisory
http://packetstormsecurity.com/files/146631/Slackware-Security-Advisory-ntp-Updates.html
Third Party Advisory
VDB Entry
http://www.securityfocus.com/archive/1/541824/100/0/threaded
Third Party Advisory
VDB Entry
https://security.FreeBSD.org/advisories/FreeBSD-SA-18:02.ntp.asc
Third Party Advisory
https://security.gentoo.org/glsa/201805-12
Third Party Advisory
https://security.netapp.com/advisory/ntap-20180626-0001/
Third Party Advisory
https://usn.ubuntu.com/3707-1/
Third Party Advisory
http://support.ntp.org/bin/view/Main/NtpBug3453
Third Party Advisory
http://www.securityfocus.com/bid/103192
Third Party Advisory
VDB Entry