Vulnerability Description
The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Net-Snmp | Net-Snmp | <= 5.4.1 |
Related Weaknesses (CWE)
References
- http://bugs.gentoo.org/show_bug.cgi?id=198346
- http://lists.vmware.com/pipermail/security-announce/2008/000014.htmlPatch
- http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/tags/Ext-5-4-1/net-snmp/agen
- http://osvdb.org/38904
- http://secunia.com/advisories/27558Vendor Advisory
- http://secunia.com/advisories/27685Vendor Advisory
- http://secunia.com/advisories/27689Vendor Advisory
- http://secunia.com/advisories/27733Vendor Advisory
- http://secunia.com/advisories/27740Vendor Advisory
- http://secunia.com/advisories/27965Vendor Advisory
- http://secunia.com/advisories/28413Vendor Advisory
- http://secunia.com/advisories/28825Vendor Advisory
- http://secunia.com/advisories/29785Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200711-31.xml
- http://sourceforge.net/project/shownotes.php?release_id=528095&group_id=12694
FAQ
What is CVE-2007-5846?
CVE-2007-5846 is a vulnerability with a CVSS score of 7.8 (HIGH). The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value.
How severe is CVE-2007-5846?
CVE-2007-5846 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-5846?
Check the references section above for vendor advisories and patch information. Affected products include: Net-Snmp Net-Snmp.