Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array.
| Software | From | Fixed in |
|---|---|---|
| ntp / ntp | 4.2.8-p9 | 4.2.8-p9.x |
| ntp / ntp | 4.2.8-p7 | 4.2.8-p7.x |
| ntp / ntp | 4.2.8-p8 | 4.2.8-p8.x |
| ntp / ntp | 4.2.8-p6 | 4.2.8-p6.x |
| ntp / ntp | 4.2.8-p10 | 4.2.8-p10.x |
| freebsd / freebsd | 10.3 | 10.3.x |
| freebsd / freebsd | 11.1 | 11.1.x |
| freebsd / freebsd | 10.4 | 10.4.x |
| canonical / ubuntu_linux | 12.04 | 12.04.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| canonical / ubuntu_linux | 17.10 | 17.10.x |
| canonical / ubuntu_linux | 18.04 | 18.04.x |