CVE-2015-5621
19.08.2015, 15:59
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.Enginsight
| Vendor | Product | Version |
|---|---|---|
| net-snmp | net-snmp | 𝑥 ≤ 5.7.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References