Database/Control plane, storage & DevOps
ntpq / ntpdc (NTP 4.2.8p11 client utilities): Stack buffer overflow in the ntpq and ntpdc command-line tools via a long
Impact
Stack buffer overflow in the ntpq and ntpdc command-line tools via a long argument, giving code execution or privilege escalation. The interesting case for a cluster operator is automation: monitoring scripts that shell out to ntpq with a hostname taken from inventory turn an inventory-poisoning bug into code execution on the monitoring host.
Who can reach it
Local, via a long argument to ntpq/ntpdc — reachable wherever these tools are invoked with externally influenced arguments.
What to do
Upgrade the ntp package. No service restart needed for the client tools; nothing to reboot. Audit any monitoring or automation that passes untrusted strings to ntpq.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.