How to address CVE-2018-12327 in Solaris 11.3
Hi All,
The said vulnerability is fixed in Oracle Solaris 11.4 SRU8 and not in any 11.3 release.
Can someone help in fixation the same in Solaris 11.3 please?
The bug was fixed on Solaris 10 via patch SPARC: 143725-12 X86: 143726-12 but not in Solaris 11.3.
more detail:
PCI Fail
NTP ntpdc and ntpq openhost() Stack-based Buffer Overflow (Bug 3505)
The detected version of NTP running on this host is known to be vulnerable to a Stack-based Buffer Overflow. Due to lack of sanitization on the input strings a local user might be able to crash the service, execute code or elevate its privileges in the context of the affected system by passing an specially crafted long string to the ntpdc and ntpq tools, which will call the openhost() method and result in the Buffer Overflow situation.