Lucene search

K
ubuntuUbuntuUSN-5795-2
HistoryJan 16, 2023 - 12:00 a.m.

Net-SNMP vulnerabilities

2023-01-1600:00:00
ubuntu.com
37
net-snmp
ubuntu 14.04
ubuntu 16.04
esm
snmp server
denial of service
arbitrary code
vulnerability
memory operations

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

8.3 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.0%

Releases

  • Ubuntu 16.04 ESM
  • Ubuntu 14.04 ESM

Packages

  • net-snmp - SNMP (Simple Network Management Protocol) server and applications

Details

USN-5795-1 and 5543-1 fixed several vulnerabilities in Net-SNMP. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

It was discovered that Net-SNMP incorrectly handled certain requests. A
remote attacker could possibly use these issues to cause Net-SNMP to crash,
resulting in a denial of service.

Yu Zhang and Nanyu Zhong discovered that Net-SNMP incorrectly handled
memory operations when processing certain requests. A remote attacker could
use this issue to cause Net-SNMP to crash, resulting in a denial of
service, or possibly execute arbitrary code.

OSVersionArchitecturePackageVersionFilename
Ubuntu16.04noarchsnmp< 5.7.3+dfsg-1ubuntu4.6+esm1UNKNOWN
Ubuntu16.04noarchlibsnmp-base< 5.7.3+dfsg-1ubuntu4.6UNKNOWN
Ubuntu16.04noarchlibsnmp-dev< 5.7.3+dfsg-1ubuntu4.6UNKNOWN
Ubuntu16.04noarchlibsnmp-dev-dbgsym< 5.7.3+dfsg-1ubuntu4.6UNKNOWN
Ubuntu16.04noarchlibsnmp-perl< 5.7.3+dfsg-1ubuntu4.6UNKNOWN
Ubuntu16.04noarchlibsnmp-perl-dbgsym< 5.7.3+dfsg-1ubuntu4.6UNKNOWN
Ubuntu16.04noarchlibsnmp30< 5.7.3+dfsg-1ubuntu4.6UNKNOWN
Ubuntu16.04noarchlibsnmp30-dbg< 5.7.3+dfsg-1ubuntu4.6UNKNOWN
Ubuntu16.04noarchlibsnmp30-dbgsym< 5.7.3+dfsg-1ubuntu4.6UNKNOWN
Ubuntu16.04noarchpython-netsnmp< 5.7.3+dfsg-1ubuntu4.6UNKNOWN
Rows per page:
1-10 of 351

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

8.3 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.0%