PT-2008-6961 · Net Snmp+1 · Net-Snmp+1

Published

1970-01-01

·

Updated

2017-09-29

·

CVE-2008-2292

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Net-SNMP versions 5.1.4 through 5.4.1 net-snmp-devel-64bit (affected versions not specified) net-snmp-x86 (affected versions not specified) net-snmp (affected versions not specified) net-snmp-64bit (affected versions not specified) net-snmp-32bit (affected versions not specified) net-snmp-devel (affected versions not specified) snmp-mibs (affected versions not specified) libsnmp15 (affected versions not specified)
Description The issue involves multiple vulnerabilities in the Net-SNMP package, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely, potentially causing a denial of service or allowing the execution of arbitrary code. The vulnerabilities are related to a buffer overflow in the snprint value function in snmp get, which can be triggered by a large OCTETSTRING in an attribute value pair.
Recommendations For Net-SNMP versions 5.1.4 through 5.4.1: Update to a version outside of this range to mitigate the risk. For net-snmp-devel-64bit: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For net-snmp-x86: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For net-snmp: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For net-snmp-64bit: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For net-snmp-32bit: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For net-snmp-devel: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For snmp-mibs: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For libsnmp15: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04275
BDU:2015-04276
BDU:2015-04277
BDU:2015-05006
BDU:2015-05007
BDU:2015-05008
BDU:2015-05009
BDU:2015-05010
BDU:2015-05011
BDU:2015-05012
BDU:2015-05013
CVE-2008-2292
DSA-1663-1
DTSA-134-1
RHSA-2008:0529
RHSA-2008_0529

Affected Products

Net-Snmp
Red Hat