ntpd version 4.2.8p10 out-of-bounds read proof of concept exploit.
c94133fbdc5e07edf27c450f7e6252957fb711ed61fe71c545825bb55d48fbd4
Ubuntu Security Notice 3707-1 - Yihan Lian discovered that NTP incorrectly handled certain malformed mode 6 packets. A remote attacker could possibly use this issue to cause ntpd to crash, resulting in a denial of service. This issue only affected Ubuntu 17.10 and Ubuntu 18.04 LTS. Michael Macnair discovered that NTP incorrectly handled certain responses. A remote attacker could possibly use this issue to execute arbitrary code. Various other issues were also addressed.
32ce831d1f1118924cb8bef066769217952aeaceb8886b1b83365b1d33fda1a3
Gentoo Linux Security Advisory 201805-12 - Multiple vulnerabilities have been found in NTP, the worst of which could lead to remote code execution. Versions less than 4.2.8_p11 are affected.
818cfb09bc153d933a492ae7af6c8d103329d790eb73e41219b8664276dd14d4
Slackware Security Advisory - New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
b9a66f00cb4f7f2a7bf96288fbec7cd2617bd1b5cb1219ca1456cb9b61cb915c