CVE-2018-7182 is an out-of-bounds read vulnerability in the ctl_getitem method of ntpd versions 4.2.8p6 through 4.2.8p10, allowing remote attackers to cause a denial of service. This vulnerability affects various products from Canonical, NetApp, and NTP. Rated with a CVSS score of 7.5 (HIGH), it requires no user interaction or authentication and has a high impact on availability. While not listed in CISA's KEV catalog, a Proof-of-Concept exploit is available on ExploitDB, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p10:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p6:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p7:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p8:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p9:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.