CVE-2015-5621
19.08.2015, 15:59
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.Enginsight
Vendor | Product | Version |
---|---|---|
net-snmp | net-snmp | 𝑥 ≤ 5.7.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References