Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Netsnmp | — | Apply OS X security update 2009-002Upgrade macOS to the latest version | Dec 16, 2011 | Oct 31, 2008 |
| Centos_linux | — | Upgrade net-snmp-utilsUpgrade net-snmpUpgrade net-snmp-libsUpgrade net-snmp-develUpgrade net-snmp-perl | Dec 1, 2016 | Oct 31, 2008 |
| Debian | — | Upgrade net-snmp | Jul 30, 2024 | Oct 31, 2008 |
| Freebsd | — | Upgrade net-snmp | Dec 10, 2025 | Nov 14, 2008 |
| Gentoo Linux | — | Upgrade net-analyzer/net-snmp. | Oct 30, 2017 | Oct 31, 2008 |
| Oracle_linux | — | Upgrade net-snmp-utilsUpgrade net-snmpUpgrade net-snmp-perlUpgrade net-snmp-libsUpgrade net-snmp-devel | Oct 16, 2024 | Oct 31, 2008 |
| Suse | — | Upgrade perl-SNMPUpgrade libsnmp15-x86Upgrade libsnmp15-32bitUpgrade libsnmp40Upgrade net-snmp-develUpgrade libsnmp15Upgrade net-snmpUpgrade snmp-mibsUpgrade libsnmp15-openssl1-32bitUpgrade python313-net-snmpUpgrade net-snmp-devel-32bitUpgrade libsnmp15-openssl1 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libsnmp-perlUpgrade libsnmp15Upgrade libsnmp9Upgrade libsnmp10 | Nov 8, 2024 | Oct 31, 2008 |
| Vmsa 2009 0001 | — | Upgrade VMware ESX 3.5 to build number 143198 | Nov 19, 2010 | Oct 31, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub