{"id":"DEBIAN-CVE-2018-12327","details":"Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. NOTE: It is unclear whether there are any common situations in which ntpq or ntpdc is used with a command line from an untrusted source.","modified":"2026-08-04T06:04:20.053815080Z","published":"2018-06-20T14:29:00.227Z","upstream":["CVE-2018-12327"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2018-12327"}],"affected":[{"package":{"name":"ntp","ecosystem":"Debian:11","purl":"pkg:deb/debian/ntp?arch=source&distro=bullseye"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:4.2.8p15+dfsg-1","1:4.2.8p15+dfsg-2-hurd.1","1:4.2.8p15+dfsg-2~1.2.1+dfsg1-7+hurd.1","1:4.2.8p15+dfsg-2~1.2.1+dfsg1-8+hurd.1","1:4.2.8p15+dfsg-2~1.2.2+dfsg1-2+hurd.1","1:4.2.8p15+dfsg-2~hurd.1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-12327.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}