vendor:
Net-SNMP
by:
Praveen Darshanam
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Net-SNMP
Affected Version From: 5.1.2004
Affected Version To: 5.4.2001
Patch Exists: NO
Related CWE: CVE-2008-2292
CPE: a:net-snmp:net-snmp:5.1.4- cpe:/a:net-snmp:net-snmp:5.2.4- cpe:/a:net-snmp:net-snmp:5.4.1
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2008-0529/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cesa-2008-0529/, https://www.rapid7.com/db/vulnerabilities/vmsa-2008-0013-cve-2008-2292/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2008-2292/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2008-2292/
Platforms Tested:
2008
Net-SNMP Buffer Overflow
Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large OCTETSTRING in an attribute value pair (AVP).
Mitigation:
Unknown