Lucene search

K
rosalinuxROSA LABROSA-SA-2024-2365
HistoryMar 05, 2024 - 8:36 a.m.

Advisory ROSA-SA-2024-2365

2024-03-0508:36:13
ROSA LAB
abf.rosalinux.ru
18
advisory
rosa-sa-2024-2365
net-snmp
vulnerabilities
medium
update
yum
fixed
null pointer exception
denial of service
udp packet

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

71.0%

Software: net-snmp 5.8
OS: ROSA Virtualization 2.1

package_evr_string: net-snmp-5.8-27.rv3

CVE-ID: CVE-2022-44792
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC.: handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP has a NULL Pointer Exception error, which could be used by a remote attacker (with write access) to cause an instance failure via a crafted UDP packet, resulting in a denial of service.
CVE-STATUS: Fixed
CVE-REV: To close, run the yum update net-snmp command

CVE-ID: CVE-2022-44793
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC.: handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP contains a NULL Pointer Exception error that can be used by a remote attacker to cause an instance failure via a crafted UDP packet, resulting in a denial of service.
CVE-STATUS: Fixed
CVE-REV: To close, run the yum update net-snmp command

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

71.0%