High severity7.5NVD Advisory· Published Mar 6, 2018· Updated Jun 17, 2026
CVE-2018-7185
CVE-2018-7185
Description
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
58cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*+ 24 more
- cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*range: >=4.2.6,<4.2.8
- cpe:2.3:a:ntp:ntp:4.2.8:-:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-beta1:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-beta2:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-beta3:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-beta4:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-beta5:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-rc1:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1-rc2:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p10:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p1:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p2-rc1:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p2-rc2:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p2-rc3:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p2:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p3-rc1:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p3-rc2:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p3-rc3:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p3:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p4:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p5:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p6:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p7:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p8:*:*:*:*:*:*
- cpe:2.3:a:ntp:ntp:4.2.8:p9:*:*:*:*:*:*
- cpe:2.3:a:synology:virtual_diskstation_manager:*:*:*:*:*:*:*:*Range: <6.1.6-15266
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:oracle:fujitsu_m10-1_firmware:*:*:*:*:*:*:*:*Range: <xcp2361
- cpe:2.3:o:oracle:fujitsu_m10-4_firmware:*:*:*:*:*:*:*:*Range: <xcp2361
- cpe:2.3:o:oracle:fujitsu_m10-4s_firmware:*:*:*:*:*:*:*:*Range: <xcp2361
- cpe:2.3:o:oracle:fujitsu_m12-1_firmware:*:*:*:*:*:*:*:*Range: <xcp2361
- cpe:2.3:o:oracle:fujitsu_m12-2_firmware:*:*:*:*:*:*:*:*Range: <xcp2361
- cpe:2.3:o:oracle:fujitsu_m12-2s_firmware:*:*:*:*:*:*:*:*Range: <xcp2361
- cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:*Range: >=5.2,<6.1.6-15266
- osv-coords14 versionspkg:rpm/opensuse/ntp&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ntp&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/ntp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/ntp&distro=SUSE%20OpenStack%20Cloud%207
< 4.2.8p15-7.2+ 13 more
- (no CPE)range: < 4.2.8p15-7.2
- (no CPE)range: < 4.2.8p11-64.5.1
- (no CPE)range: < 4.2.8p11-64.3.2
- (no CPE)range: < 4.2.8p11-64.4.1
- (no CPE)range: < 4.2.8p11-64.5.1
- (no CPE)range: < 4.2.8p11-64.5.1
- (no CPE)range: < 4.2.8p11-64.5.1
- (no CPE)range: < 4.2.8p11-64.3.2
- (no CPE)range: < 4.2.8p11-46.26.2
- (no CPE)range: < 4.2.8p11-64.4.1
- (no CPE)range: < 4.2.8p11-64.5.1
- (no CPE)range: < 4.2.8p11-64.5.1
- (no CPE)range: < 4.2.8p11-64.3.2
- (no CPE)range: < 4.2.8p11-64.5.1
Patches
Vulnerability mechanics
References
12- packetstormsecurity.com/files/146631/Slackware-Security-Advisory-ntp-Updates.htmlnvdThird Party AdvisoryVDB Entry
- support.ntp.org/bin/view/Main/NtpBug3454nvdMitigationVendor Advisory
- www.securityfocus.com/archive/1/541824/100/0/threadednvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/103339nvdThird Party AdvisoryVDB Entry
- security.freebsd.org/advisories/FreeBSD-SA-18:02.ntp.ascnvdThird Party Advisory
- security.gentoo.org/glsa/201805-12nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20180626-0001/nvdThird Party Advisory
- support.hpe.com/hpsc/doc/public/displaynvdThird Party Advisory
- usn.ubuntu.com/3707-1/nvdThird Party Advisory
- usn.ubuntu.com/3707-2/nvdThird Party Advisory
- www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlnvdThird Party Advisory
- www.synology.com/support/security/Synology_SA_18_13nvdThird Party Advisory
News mentions
0No linked articles in our index yet.