Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5621

Опубликовано: 13 апр. 2015
Источник: redhat
CVSS2: 5.1
EPSS Средний

Описание

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

It was discovered that the snmp_pdu_parse() function could leave incompletely parsed varBind variables in the list of variables. A remote, unauthenticated attacker could use this flaw to crash snmpd or, potentially, execute arbitrary code on the system with the privileges of the user running snmpd.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-772->CWE-672->CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=1212408net-snmp: snmp_pdu_parse() incompletely parsed varBinds left in list of variables

EPSS

Процентиль: 95%
0.19209
Средний

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

nvd
около 10 лет назад

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

debian
около 10 лет назад

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlie ...

suse-cvrf
около 10 лет назад

Security update for net-snmp

suse-cvrf
около 10 лет назад

Security update for net-snmp

EPSS

Процентиль: 95%
0.19209
Средний

5.1 Medium

CVSS2