suse · CVE-2018-7182

Quick triage

Priority: medium Published: 2021-05-30 14:11:06 UTC Updated: 2026-04-17 15:31:38 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-7182 severity moderate: SUSE including 28 source package names (libntpc1-1.2.1-1.2, ntp, …), 92 product×package rows across 61 product lines (Image SLES12-SP5-Azure-BYOS, Image SLES12-SP5-Azure-Basic-On-Demand, … (61 product lines)): Fixed 81, Known Not Affected 11.

Description:

The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10.

cvelogic Threat Intelligence