CVE-2012-2141
published 2012-08-14CVE-2012-2141: Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a…
PriorityP412low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
2.17%
80.3th percentile
Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | net-snmp | < net-snmp 5.4.3~dfsg-2.5 (bookworm) | net-snmp 5.4.3~dfsg-2.5 (bookworm) |
| net-snmp | net-snmp | — | — |
| net-snmp | net-snmp | >= 0 < 5.4.3~dfsg-2.5 | 5.4.3~dfsg-2.5 |
| net-snmp | net-snmp | >= 0 < 5.4.3~dfsg-2.5 | 5.4.3~dfsg-2.5 |
| net-snmp | net-snmp | >= 0 < 5.4.3~dfsg-2.5 | 5.4.3~dfsg-2.5 |
| net-snmp | net-snmp | >= 0 < 5.4.3~dfsg-2.5 | 5.4.3~dfsg-2.5 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qx3h-g3gw-6vrx: Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend
ghsa_unreviewed·2022-05-17
CVE-2012-2141 [LOW] GHSA-qx3h-g3gw-6vrx: Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend
Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.
OSV
CVE-2012-2141: Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend
osv·2012-08-14·CVSS 3.5
CVE-2012-2141 [LOW] CVE-2012-2141: Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend
Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.
Ubuntu
Net-SNMP vulnerability
vendor_ubuntu·2012-05-23
CVE-2012-2141 Net-SNMP vulnerability
Title: Net-SNMP vulnerability
Summary: Net-SNMP could be made to crash if it received specially crafted network
traffic.
It was discovered that Net-SNMP incorrectly performed entry lookups in the
extension table. A remote attacker could send a specially crafted request
and cause the SNMP server to crash, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
net-snmp: Array index error, leading to out-of heap-based buffer read (snmpd crash)
vendor_redhat·2012-04-24·CVSS 3.5
CVE-2012-2141 [LOW] net-snmp: Array index error, leading to out-of heap-based buffer read (snmpd crash)
net-snmp: Array index error, leading to out-of heap-based buffer read (snmpd crash)
Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.
Debian
CVE-2012-2141: net-snmp - Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/...
vendor_debian·2012·CVSS 3.5
CVE-2012-2141 [LOW] CVE-2012-2141: net-snmp - Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/...
Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.
Scope: local
bookworm: resolved (fixed in 5.4.3~dfsg-2.5)
bullseye: resolved (fixed in 5.4.3~dfsg-2.5)
forky: resolved (fixed in 5.4.3~dfsg-2.5)
sid: resolved (fixed in 5.4.3~dfsg-2.5)
trixie: resolved (fixed in 5.4.3~dfsg-2.5)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-0124.htmlhttp://secunia.com/advisories/48938http://secunia.com/advisories/59974http://support.citrix.com/article/CTX139049http://www.gentoo.org/security/en/glsa/glsa-201409-02.xmlhttp://www.openwall.com/lists/oss-security/2012/04/26/2http://www.openwall.com/lists/oss-security/2012/04/26/3http://www.securityfocus.com/bid/53255http://www.securityfocus.com/bid/53258http://www.securitytracker.com/id?1026984https://bugzilla.redhat.com/show_bug.cgi?id=815813https://exchange.xforce.ibmcloud.com/vulnerabilities/75169http://rhn.redhat.com/errata/RHSA-2013-0124.htmlhttp://secunia.com/advisories/48938http://secunia.com/advisories/59974http://support.citrix.com/article/CTX139049http://www.gentoo.org/security/en/glsa/glsa-201409-02.xmlhttp://www.openwall.com/lists/oss-security/2012/04/26/2http://www.openwall.com/lists/oss-security/2012/04/26/3http://www.securityfocus.com/bid/53255http://www.securityfocus.com/bid/53258http://www.securitytracker.com/id?1026984https://bugzilla.redhat.com/show_bug.cgi?id=815813https://exchange.xforce.ibmcloud.com/vulnerabilities/75169
2012-08-14
Published