Описание
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).
A double-free vulnerability was found in the csnmp_read_table function in the SNMP plugin of collectd. A network-based attacker could exploit this by sending malformed data, causing collectd to crash or possibly other impact.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 2 | collectd | Affected | ||
| Red Hat Ceph Storage 3 | collectd | Affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | collectd | Will not fix | ||
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | collectd | Will not fix | ||
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | collectd | Will not fix | ||
| Red Hat Storage Console 2 | collectd | Will not fix | ||
| Red Hat Gluster Storage 3.4 for RHEL 7 | collectd | Fixed | RHSA-2018:2615 | 04.09.2018 |
| Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7 | collectd | Fixed | RHSA-2018:1605 | 17.05.2018 |
| Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7 | intel-cmt-cat | Fixed | RHSA-2018:1605 | 17.05.2018 |
| Red Hat OpenStack Platform 11.0 Operational Tools for RHEL 7 | collectd | Fixed | RHSA-2018:0299 | 13.02.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.6 Medium
CVSS3
Связанные уязвимости
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd ...
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).
Уязвимость функции csnmp_read_table (snmp.c) SNMP-плагина демона Сollectd, позволяющая нарушителю вызвать аварийное завершение работы приложения
EPSS
5.6 Medium
CVSS3