CVE-2015-5621
Published: 31 July 2015
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
Priority
Status
Package | Release | Status |
---|---|---|
net-snmp Launchpad, Ubuntu, Debian |
upstream |
Needed
|
precise |
Released
(5.4.3~dfsg-2.4ubuntu1.3)
|
|
trusty |
Released
(5.7.2~dfsg-8.1ubuntu3.1)
|
|
vivid |
Released
(5.7.2~dfsg-8.1ubuntu5.1)
|
|
Patches: upstream: http://sourceforge.net/p/net-snmp/code/ci/f23bcd3ac6ddee5d0a48f9703007ccc738914791/ |