CVE-2008-4309
published 2008-10-31CVE-2008-4309: Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.97%
91.3th percentile
Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | net-snmp | < net-snmp 5.4.1~dfsg-11 (bookworm) | net-snmp 5.4.1~dfsg-11 (bookworm) |
| debian | net-snmp | — | — |
| net-snmp | net-snmp | — | — |
| net-snmp | net-snmp | — | — |
| net-snmp | net-snmp | — | — |
| net-snmp | net-snmp | — | — |
| net-snmp | net-snmp | >= 0 < 5.4.1~dfsg-11 | 5.4.1~dfsg-11 |
| net-snmp | net-snmp | >= 0 < 5.4.1~dfsg-11 | 5.4.1~dfsg-11 |
| net-snmp | net-snmp | >= 0 < 5.4.1~dfsg-11 | 5.4.1~dfsg-11 |
| net-snmp | net-snmp | >= 0 < 5.4.1~dfsg-11 | 5.4.1~dfsg-11 |
| vmware | vmware_esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_ubuntu10.0CRITICAL
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
net-snmp: DoS (division by zero) via SNMP GetBulk requests
vendor_redhat·2009-06-25·CVSS 5.0
CVE-2009-1887 [MEDIUM] net-snmp: DoS (division by zero) via SNMP GetBulk requests
net-snmp: DoS (division by zero) via SNMP GetBulk requests
agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP GETBULK request that triggers a divide-by-zero error. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-4309.
VMware
ESX patches address an issue loading corrupt virtual disks and update Service Console packages
vendor_vmware·2009-01-30·CVSS 4.7
CVE-2008-4225 [MEDIUM] ESX patches address an issue loading corrupt virtual disks and update Service Console packages
VMSA-2009-0001: ESX patches address an issue loading corrupt virtual disks and update Service Console packages
a. Loading a corrupt delta disk may cause ESX to crash If the VMDK delta disk of a snapshot is corrupt, an ESX host might crash when the corrupted disk is loaded. VMDK delta files exist for virtual machines with one or more snapshots. This change ensures that a corrupt VMDK delta file cannot be used to crash ESX hosts. A corrupt VMDK delta disk, or virtual machine would have to be loaded by an administrator. VMware would like to thank Craig Marshall for reporting this issue. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the name CVE-2008-4914 to this issue. The following table lists what action remediates the vulnerability (column 4) if a solution
Debian
CVE-2009-1887: net-snmp - agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL)...
vendor_debian·2009·CVSS 5.0
CVE-2009-1887 [MEDIUM] CVE-2009-1887: net-snmp - agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL)...
agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP GETBULK request that triggers a divide-by-zero error. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-4309.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Ubuntu
Net-SNMP vulnerabilities
vendor_ubuntu·2008-12-03·CVSS 10.0
CVE-2008-0960 [CRITICAL] Net-SNMP vulnerabilities
Title: Net-SNMP vulnerabilities
Summary: Net-SNMP vulnerabilities
Wes Hardaker discovered that the SNMP service did not correctly validate
HMAC authentication requests. An unauthenticated remote attacker
could send specially crafted SNMPv3 traffic with a valid username
and gain access to the user's views without a valid authentication
passphrase. (CVE-2008-0960)
John Kortink discovered that the Net-SNMP Perl module did not correctly
check the size of returned values. If a user or automated system were
tricked into querying a malicious SNMP server, the application using
the Perl module could be made to crash, leading to a denial of service.
This did not affect Ubuntu 8.10. (CVE-2008-2292)
It was discovered that the SNMP service did not correctly handle large
GETBULK requests. If an unau
Red Hat
net-snmp: numresponses calculation integer overflow in snmp_agent.c
vendor_redhat·2008-10-31·CVSS 5.0
CVE-2008-4309 [MEDIUM] CWE-190 net-snmp: numresponses calculation integer overflow in snmp_agent.c
net-snmp: numresponses calculation integer overflow in snmp_agent.c
Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.
Debian
CVE-2008-4309: net-snmp - Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agen...
vendor_debian·2008·CVSS 5.0
CVE-2008-4309 [MEDIUM] CVE-2008-4309: net-snmp - Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agen...
Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.
Scope: local
bookworm: resolved (fixed in 5.4.1~dfsg-11)
bullseye: resolved (fixed in 5.4.1~dfsg-11)
forky: resolved (fixed in 5.4.1~dfsg-11)
sid: resolved (fixed in 5.4.1~dfsg-11)
trixie: resolved (fixed in 5.4.1~dfsg-11)
GHSA
GHSA-cf72-rgjq-hh5r: agent/snmp_agent
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2009-1887 [MEDIUM] CWE-369 GHSA-cf72-rgjq-hh5r: agent/snmp_agent
agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP GETBULK request that triggers a divide-by-zero error. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-4309.
GHSA
GHSA-c4mx-98gv-gxm8: Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent
ghsa_unreviewed·2022-05-02
CVE-2008-4309 [MEDIUM] CWE-20 GHSA-c4mx-98gv-gxm8: Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent
Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.
OSV
CVE-2008-4309: Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent
osv·2008-10-31·CVSS 5.0
CVE-2008-4309 [MEDIUM] CVE-2008-4309: Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent
Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1887 net-snmp: DoS (division by zero) via SNMP GetBulk requests
bugzilla·2009-06-19·CVSS 5.0
CVE-2009-1887 [MEDIUM] CVE-2009-1887 net-snmp: DoS (division by zero) via SNMP GetBulk requests
CVE-2009-1887 net-snmp: DoS (division by zero) via SNMP GetBulk requests
It was discovered that remote attacker can cause net-snmp's snmpd to crash via specially crafted SNMP GetBulk requests, that triggers division by zero in the following code:
if (maxbulk maxresponses / r)
maxbulk = maxresponses / r;
This code has been added as part of the fix for CVE-2008-4309 (bug #469349). This problem never affected upstream net-snmp versions, thanks to following upstream commit from 2004:
http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/trunk/net-snmp/agent/snmp_agent.c?r1=9583&r2=9695
This upstream change is part of net-snmp packages shipped in Red Hat Enterprise Linux 4 and later. Therefore this division by zero DoS only affects net-snmp in Red Hat Enterprise Linux 3.
Discussion:
This i
Bugzilla
CVE-2008-4309 net-snmp: numresponses calculation integer overflow in snmp_agent.c
bugzilla·2008-10-31·CVSS 5.0
CVE-2008-4309 [MEDIUM] CVE-2008-4309 net-snmp: numresponses calculation integer overflow in snmp_agent.c
CVE-2008-4309 net-snmp: numresponses calculation integer overflow in snmp_agent.c
Oscar Mira-Sanchez reported (via TippingPoint/ZDI) to Net-SNMP upstream an integer overflow in the numresponses calculation in snmp_agent.c. Size of memory requirement for bulkcache array is calculated based on the values form an SNMP request without properly checking for integer overflows, resulting in an insufficient memory allocation and heap-based buffer overflow.
agent/snmp_agent.c:
numresponses = asp->pdu->errindex * r;
[ ... ]
asp->bulkcache =
(netsnmp_variable_list **) malloc(numresponses *
sizeof(struct
varbind_list *));
Issue can be triggered by an SNMP get request.
Discussion:
Upstream SVN commit:
http://net-snmp.svn.sourceforge.net/viewvc/net-snmp?view=rev&revision=17272
---
This is goin
http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010//Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.htmlhttp://marc.info/?l=bugtraq&m=125017764422557&w=2http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/tags/Ext-5-2-5-1/net-snmp/agent/snmp_agent.c?r1=17271&r2=17272&pathrev=17272http://secunia.com/advisories/32539http://secunia.com/advisories/32560http://secunia.com/advisories/32664http://secunia.com/advisories/32711http://secunia.com/advisories/33003http://secunia.com/advisories/33095http://secunia.com/advisories/33631http://secunia.com/advisories/33746http://secunia.com/advisories/33821http://secunia.com/advisories/35074http://secunia.com/advisories/35679http://security.gentoo.org/glsa/glsa-200901-15.xmlhttp://sourceforge.net/forum/forum.php?forum_id=882903http://sunsolve.sun.com/search/document.do?assetkey=1-26-262908-1http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT4298http://support.avaya.com/elmodocs2/security/ASA-2008-467.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0315http://www.debian.org/security/2008/dsa-1663http://www.mandriva.com/security/advisories?name=MDVSA-2008:225http://www.openwall.com/lists/oss-security/2008/10/31/1http://www.redhat.com/support/errata/RHSA-2008-0971.htmlhttp://www.securityfocus.com/archive/1/498280/100/0/threadedhttp://www.securityfocus.com/bid/32020http://www.securitytracker.com/id?1021129http://www.ubuntu.com/usn/usn-685-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vmware.com/security/advisories/VMSA-2009-0001.htmlhttp://www.vupen.com/english/advisories/2008/2973http://www.vupen.com/english/advisories/2008/3400http://www.vupen.com/english/advisories/2009/0301http://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1771https://exchange.xforce.ibmcloud.com/vulnerabilities/46262https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6171https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6353https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9860http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010//Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.htmlhttp://marc.info/?l=bugtraq&m=125017764422557&w=2http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/tags/Ext-5-2-5-1/net-snmp/agent/snmp_agent.c?r1=17271&r2=17272&pathrev=17272http://secunia.com/advisories/32539http://secunia.com/advisories/32560http://secunia.com/advisories/32664http://secunia.com/advisories/32711http://secunia.com/advisories/33003http://secunia.com/advisories/33095http://secunia.com/advisories/33631http://secunia.com/advisories/33746http://secunia.com/advisories/33821http://secunia.com/advisories/35074http://secunia.com/advisories/35679http://security.gentoo.org/glsa/glsa-200901-15.xmlhttp://sourceforge.net/forum/forum.php?forum_id=882903http://sunsolve.sun.com/search/document.do?assetkey=1-26-262908-1http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT4298http://support.avaya.com/elmodocs2/security/ASA-2008-467.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2008-0315http://www.debian.org/security/2008/dsa-1663http://www.mandriva.com/security/advisories?name=MDVSA-2008:225http://www.openwall.com/lists/oss-security/2008/10/31/1http://www.redhat.com/support/errata/RHSA-2008-0971.htmlhttp://www.securityfocus.com/archive/1/498280/100/0/threadedhttp://www.securityfocus.com/bid/32020http://www.securitytracker.com/id?1021129http://www.ubuntu.com/usn/usn-685-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vmware.com/security/advisories/VMSA-2009-0001.htmlhttp://www.vupen.com/english/advisories/2008/2973http://www.vupen.com/english/advisories/2008/3400http://www.vupen.com/english/advisories/2009/0301http://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1771https://exchange.xforce.ibmcloud.com/vulnerabilities/46262https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6171https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6353https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9860
2008-10-31
Published