The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
References
Configurations
Information
Published : 2015-08-19 08:59
Updated : 2018-10-10 03:29
NVD link : CVE-2015-5621
Mitre link : CVE-2015-5621
JSON object : View
CWE
CWE-19
Data Processing Errors
Products Affected
net-snmp
- net-snmp