net-snmp is vulnerable to denial of service. This is due to a lack of validation for active requests queued when the subagent disconnects from the snmpd
, which leads to an infinite loop or crash occurs when AgentX
registers to handle an MIB
and processes GETNEXT
requests.
kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
lists.apple.com/archives/security-announce/2015/Oct/msg00005.html
seclists.org/oss-sec/2013/q4/398
seclists.org/oss-sec/2013/q4/415
secunia.com/advisories/55804
secunia.com/advisories/57870
secunia.com/advisories/59974
sourceforge.net/p/net-snmp/bugs/2411/
www.gentoo.org/security/en/glsa/glsa-201409-02.xml
www.securityfocus.com/bid/64048
www.ubuntu.com/usn/USN-2166-1
access.redhat.com/security/cve/CVE-2012-6151
bugzilla.redhat.com/show_bug.cgi?id=1038007
bugzilla.redhat.com/show_bug.cgi?id=993579
exchange.xforce.ibmcloud.com/vulnerabilities/89485
rhn.redhat.com/errata/RHBA-2013-1150.html
rhn.redhat.com/errata/RHSA-2014-0322.html
support.apple.com/HT205375