CVE-2019-20892 — Double Free in Net-snmp
Severity
6.5MEDIUMNVD
EPSS
0.5%
top 33.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 25
Latest updateMay 24
Description
net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6
Affected Packages4 packages
Patches
🔴Vulnerability Details
4📋Vendor Advisories
4Microsoft▶
net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Lin↗2020-06-09
Red Hat▶
net-snmp: double free in usm_free_usmStateReference function in snmplib/snmpusm.c via an SNMPv3 GetBulk request↗2020-01-02
Debian▶
CVE-2019-20892: net-snmp - net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in sn...↗2019
💬Community
2Bugzilla▶
CVE-2019-20892 net-snmp: double free in usm_free_usmStateReference function in snmplib/snmpusm.c via an SNMPv3 GetBulk request↗2020-06-25
Bugzilla▶
CVE-2019-20892 net-snmp: double free in usm_free_usmStateReference function in snmplib/snmpusm.c via an SNMPv3 GetBulk request [fedora-all]↗2020-06-25