Severity
9.8CRITICALNVD
OSV9.1
EPSS
3.4%
top 12.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 14
Latest updateMay 14

Description

The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

debiandebian/collectd< collectd 5.8.0-1 (bookworm)
NVDcollectd/collectd< 5.6.3
Debiancollectd/collectd< 5.8.0-1+3
Ubuntucollectd/collectd< 5.4.0-3ubuntu2.2+esm1+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fh5v-r835-mw7v: The csnmp_read_table function in snmp2022-05-14
OSV
collectd vulnerabilities2021-03-15
OSV
CVE-2017-16820: The csnmp_read_table function in snmp2017-11-14

📋Vendor Advisories

3
Ubuntu
collectd vulnerabilities2021-03-15
Red Hat
collectd: double free in csnmp_read_table function in snmp.c2017-11-14
Debian
CVE-2017-16820: collectd - The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5....2017

💬Community

4
Bugzilla
CVE-2017-16820 collectd: double free in csnmp_read_table function in snmp.c [epel-7]2017-11-22
Bugzilla
CVE-2017-16820 collectd: double free in csnmp_read_table function in snmp.c2017-11-22
Bugzilla
CVE-2017-16820 collectd: double free in csnmp_read_table function in snmp.c [epel-6]2017-11-22
Bugzilla
CVE-2017-16820 collectd: double free in csnmp_read_table function in snmp.c [fedora-all]2017-11-22