Net-SNMP: Denial of service A vulnerability in Net-SNMP could lead to a Denial of Service. net-snmp 2009-01-21 2009-01-21 245306 remote 5.4.2.1 5.4.2.1

Net-SNMP is a collection of tools for generating and retrieving SNMP data.

Oscar Mira-Sanchez reported an integer overflow in the netsnmp_create_subtree_cache() function in agent/snmp_agent.c when processing GETBULK requests.

A remote attacker could send a specially crafted request to crash the SNMP server. NOTE: The attacker needs to know the community string to exploit this vulnerability.

Restrict access to trusted entities only.

All Net-SNMP users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/net-snmp-5.4.2.1"
CVE-2008-4309 p-y p-y p-y