Release date:
Updated on: 2012-04-27
Affected Systems:
Net-SNMP net-snmp
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53255
Net-SNMP is a free, open-source SNMP implementation, formerly called UCD-SNMP.
The Net-SNMP proxy has an array index error when searching for entries in the extended table, which can cause the heap buffer overflow read vulnerability. When the extend Command processes some MIB sub-trees, If a remote attacker can read the sub-tree, this vulnerability can be exploited to cause denial-of-service by using an extension table entry that does not exist in the snmp get request.
<* Source: vendor
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 815813
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Net-SNMP
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://sourceforge.net/projects/net-snmp/