CVE-2018-1000116
published 2018-03-07CVE-2018-1000116: NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.
PriorityP352critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.41%
92.9th percentile
NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | net-snmp | < net-snmp 5.7.3+dfsg-1.1 (bookworm) | net-snmp 5.7.3+dfsg-1.1 (bookworm) |
| net-snmp | net-snmp | — | — |
| net-snmp | net-snmp | >= 0 < 5.7.3+dfsg-1.1 | 5.7.3+dfsg-1.1 |
| net-snmp | net-snmp | >= 0 < 5.7.3+dfsg-1.1 | 5.7.3+dfsg-1.1 |
| net-snmp | net-snmp | >= 0 < 5.7.3+dfsg-1.1 | 5.7.3+dfsg-1.1 |
| net-snmp | net-snmp | >= 0 < 5.7.3+dfsg-1.1 | 5.7.3+dfsg-1.1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
net-snmp: Heap corruption in snmp_pdu_parse function in snmplib/snmp_api.c
vendor_redhat·2018-03-07·CVSS 9.8
CVE-2018-1000116 [CRITICAL] CWE-20 net-snmp: Heap corruption in snmp_pdu_parse function in snmplib/snmp_api.c
net-snmp: Heap corruption in snmp_pdu_parse function in snmplib/snmp_api.c
NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.
It was discovered that the snmp_pdu_parse() mishandles error codes and is vulnerable to a heap corruption within the parsing of the PDU prior to the authentication process. A remote, unauthenticated attacker could use this flaw to crash snmpd or, potentially, execute arbitrary code on the system with the privileges of the user running snmpd.
Package: net-snmp (Red Hat Enterprise Linux 5) - Will not fix
Package: net-snmp (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-1000116: net-snmp - NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP proto...
vendor_debian·2018·CVSS 9.8
CVE-2018-1000116 [CRITICAL] CVE-2018-1000116: net-snmp - NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP proto...
NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.
Scope: local
bookworm: resolved (fixed in 5.7.3+dfsg-1.1)
bullseye: resolved (fixed in 5.7.3+dfsg-1.1)
forky: resolved (fixed in 5.7.3+dfsg-1.1)
sid: resolved (fixed in 5.7.3+dfsg-1.1)
trixie: resolved (fixed in 5.7.3+dfsg-1.1)
GHSA
GHSA-8q7v-xf4g-8vpc: NET-SNMP version 5
ghsa_unreviewed·2022-05-13
CVE-2018-1000116 [CRITICAL] CWE-787 GHSA-8q7v-xf4g-8vpc: NET-SNMP version 5
NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.
OSV
CVE-2018-1000116: NET-SNMP version 5
osv·2018-03-07·CVSS 9.8
CVE-2018-1000116 [CRITICAL] CVE-2018-1000116: NET-SNMP version 5
NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000116 net-snmp: Heap corruption in snmp_pdu_parse function in snmplib/snmp_api.c [fedora-all]
bugzilla·2018-03-07·CVSS 9.8
CVE-2018-1000116 [CRITICAL] CVE-2018-1000116 net-snmp: Heap corruption in snmp_pdu_parse function in snmplib/snmp_api.c [fedora-all]
CVE-2018-1000116 net-snmp: Heap corruption in snmp_pdu_parse function in snmplib/snmp_api.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-1000116 net-snmp: Heap corruption in snmp_pdu_parse function in snmplib/snmp_api.c
bugzilla·2018-03-07·CVSS 7.5
CVE-2018-1000116 [HIGH] CVE-2018-1000116 net-snmp: Heap corruption in snmp_pdu_parse function in snmplib/snmp_api.c
CVE-2018-1000116 net-snmp: Heap corruption in snmp_pdu_parse function in snmplib/snmp_api.c
The version 5.7.2 was vulnerable to a heap corruption within the parsing of the PDU prior to the authentication process.
Upstream issue:
https://sourceforge.net/p/net-snmp/bugs/2821/
Upstream patch:
https://sourceforge.net/p/net-snmp/code/ci/f23bcd3ac6ddee5d0a48f9703007ccc738914791/
Discussion:
Created net-snmp tracking bugs for this issue:
Affects: fedora-all [bug 1552845]
---
The "upstream patch" linked in Comment 0 is the same as for Bug 1212408, which was CVE-2015-5621.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2015:1636: https://access.redhat.com/errata/RHSA-2015:1636
---
External References:
http
https://lists.debian.org/debian-lts-announce/2018/03/msg00020.htmlhttps://sourceforge.net/p/net-snmp/bugs/2821/https://www.debian.org/security/2018/dsa-4154https://lists.debian.org/debian-lts-announce/2018/03/msg00020.htmlhttps://sourceforge.net/p/net-snmp/bugs/2821/https://www.debian.org/security/2018/dsa-4154
2018-03-07
Published