Vulnerability Description
Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Net-Snmp | Net-Snmp | 5.2.5 |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
- http://lists.apple.com/archives/security-announce/2010//Dec/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html
- http://marc.info/?l=bugtraq&m=125017764422557&w=2
- http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/tags/Ext-5-2-5-1/net-snmp/agVendor Advisory
- http://secunia.com/advisories/32539
- http://secunia.com/advisories/32560
- http://secunia.com/advisories/32664
- http://secunia.com/advisories/32711
- http://secunia.com/advisories/33003
- http://secunia.com/advisories/33095
- http://secunia.com/advisories/33631
- http://secunia.com/advisories/33746
- http://secunia.com/advisories/33821
- http://secunia.com/advisories/35074
FAQ
What is CVE-2008-4309?
CVE-2008-4309 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial...
How severe is CVE-2008-4309?
CVE-2008-4309 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-4309?
Check the references section above for vendor advisories and patch information. Affected products include: Net-Snmp Net-Snmp.