cbcvebase.
CVE-2018-18065
published 2018-10-08

CVE-2018-18065: _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely…

medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EXPLOIT
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiannet-snmp< net-snmp 5.7.3+dfsg-4 (bookworm)net-snmp 5.7.3+dfsg-4 (bookworm)
net-snmpnet-snmp< 5.85.8
net-snmpnet-snmp>= 0 < 5.7.3+dfsg-45.7.3+dfsg-4
net-snmpnet-snmp>= 0 < 5.7.3+dfsg-45.7.3+dfsg-4
net-snmpnet-snmp>= 0 < 5.7.3+dfsg-45.7.3+dfsg-4
net-snmpnet-snmp>= 0 < 5.7.3+dfsg-45.7.3+dfsg-4
netappe-series_santricity_os_controller11.0 – 11.5
paloaltopan-os
paloaltonetworkspan-os<= 7.1.22
paloaltonetworkspan-os7.1.23 – 8.0.15
paloaltonetworkspan-os8.0.16 – 8.1.6

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM