PT-2018-3134 · Net Snmp+2 · Net-Snmp+2

Magnusstubman

·

Published

2018-10-08

·

Updated

2020-04-08

·

CVE-2018-18066

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Net-SNMP versions prior to 5.8
Description The issue is related to a NULL Pointer Exception bug in the snmp oid compare function. This bug can be exploited by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
Recommendations For Net-SNMP versions prior to 5.8, update to version 5.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the snmp oid compare function to minimize the risk of exploitation.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04208
CESA-2020_1081
CVE-2018-18066
RHSA-2020:1081
RHSA-2020:2539
RHSA-2020_1081

Affected Products

Centos
Net-Snmp
Red Hat