Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Andrés López Luksenberg

Researcher fromCore Security Technologies
#35000of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2010-1033
7.5
2010-10-27
Libsmi · Libsmi · CVE-2010-2891
**Name of the Vulnerable Software and Affected Versions** libsmi versions prior to 0.4.8 **Description** The issue affects the libsmi package, potentially leading to breaches of confidentiality, integrity, and availability of protected information. It can be exploited remotely. The problem is caused by a buffer overflow in the smiGetNode function, allowing attackers to execute arbitrary code via a specially crafted Object Identifier. **Recommendations** For versions prior to 0.4.8, update to version 0.4.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the smiGetNode function until a patch is available.