Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20892

Опубликовано: 02 янв. 2020
Источник: redhat
CVSS3: 6.5

Описание

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5net-snmpNot affected
Red Hat Enterprise Linux 6net-snmpNot affected
Red Hat Enterprise Linux 7net-snmpNot affected
Red Hat Enterprise Linux 9net-snmpNot affected
Red Hat Enterprise Linux 8net-snmpFixedRHBA-2020:137607.04.2020
Red Hat Enterprise Linux 8net-snmpFixedRHBA-2020:137607.04.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1851145net-snmp: double free in usm_free_usmStateReference function in snmplib/snmpusm.c via an SNMPv3 GetBulk request

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.

CVSS3: 6.5
nvd
больше 5 лет назад

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.

CVSS3: 6.5
msrc
больше 5 лет назад

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions but might not affect an upstream release.

CVSS3: 6.5
debian
больше 5 лет назад

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateRefer ...

CVSS3: 6.5
github
больше 3 лет назад

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.

6.5 Medium

CVSS3