CVE-2016-2518

CWE-125Out-of-bounds Read11 documents10 sources
Severity
5.3MEDIUM
EPSS
2.0%
top 16.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30
Latest updateMay 13

Description

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages7 packages

NVDntp/ntp4.3.04.3.92+2
Debianntp< 1:4.2.8p7+dfsg-1
NVDoracle/linux6, 7+1

Also affects: Freebsd 10.1, 10.2, 10.3, 9.3, Debian Linux 10.0, 8.0, 9.0, Enterprise Linux 7.2, 7.4, 7.6, 7.3, 7.5, 7.7

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9cgg-qq3h-mgcv: The MATCH_ASSOC function in NTP before version 42022-05-13
OSV
CVE-2016-2518: The MATCH_ASSOC function in NTP before version 42017-01-30
CVEList
CVE-2016-2518: The MATCH_ASSOC function in NTP before version 42017-01-30

📋Vendor Advisories

5
Ubuntu
NTP vulnerabilities2016-10-05
BSD
FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp2016-04-29
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 20162016-04-28
Red Hat
ntp: out-of-bounds references on crafted packet2016-04-26
Debian
CVE-2016-2518: ntp - The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 a...2016

💬Community

2
Bugzilla
CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]2016-05-02
Bugzilla
CVE-2016-2518 ntp: out-of-bounds references on crafted packet2016-04-28