CVE-2008-4309

Impact:
Important
Public Date:
2008-10-31
CWE:
CWE-190
Bugzilla:
469349: CVE-2008-4309 net-snmp: numresponses calculation integer overflow in snmp_agent.c

The MITRE CVE dictionary describes this issue as:

Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.

Find out more about CVE-2008-4309 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 5 (net-snmp) RHSA-2008:0971 2008-11-03
Red Hat Enterprise Linux 3 (net-snmp) RHSA-2008:0971 2008-11-03
Red Hat Enterprise Linux 4 (net-snmp) RHSA-2008:0971 2008-11-03

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.