CVE-2019-20892Double Free in Net-snmp

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 33.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 25
Latest updateMay 24

Description

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

Debiannet-snmp/net-snmp< 5.8+dfsg-3+3
Ubuntunet-snmp/net-snmp< 5.8+dfsg-2ubuntu2.1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-8q2p-wr8q-hv7c: net-snmp before 52022-05-24
OSV
net-snmp vulnerability2020-07-02
CVEList
CVE-2019-20892: net-snmp before 52020-06-25
OSV
CVE-2019-20892: net-snmp before 52020-06-25

📋Vendor Advisories

4
Ubuntu
Net-SNMP vulnerability2020-07-02
Microsoft
net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Lin2020-06-09
Red Hat
net-snmp: double free in usm_free_usmStateReference function in snmplib/snmpusm.c via an SNMPv3 GetBulk request2020-01-02
Debian
CVE-2019-20892: net-snmp - net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in sn...2019

💬Community

2
Bugzilla
CVE-2019-20892 net-snmp: double free in usm_free_usmStateReference function in snmplib/snmpusm.c via an SNMPv3 GetBulk request2020-06-25
Bugzilla
CVE-2019-20892 net-snmp: double free in usm_free_usmStateReference function in snmplib/snmpusm.c via an SNMPv3 GetBulk request [fedora-all]2020-06-25
CVE-2019-20892 — Double Free in Net-snmp | cvebase