Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-5621

Опубликовано: 19 авг. 2015
Источник: debian
EPSS Средний

Описание

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
net-snmpfixed5.7.3+dfsg-1.1package
net-snmpno-dsasqueezepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2015/04/13/1

  • Upstream patch: https://sourceforge.net/p/net-snmp/code/ci/f23bcd3ac6ddee5d0a48f9703007ccc738914791/

  • https://sourceforge.net/p/net-snmp/bugs/2615/ (currently not public)

EPSS

Процентиль: 95%
0.19575
Средний

Связанные уязвимости

ubuntu
около 10 лет назад

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

redhat
больше 10 лет назад

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

nvd
около 10 лет назад

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

suse-cvrf
около 10 лет назад

Security update for net-snmp

suse-cvrf
около 10 лет назад

Security update for net-snmp

EPSS

Процентиль: 95%
0.19575
Средний