Debian Net-Snmp vulnerabilities
31 known vulnerabilities affecting debian/net-snmp.
Total CVEs
31
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5MEDIUM19LOW5
Vulnerabilities
Page 2 of 2
CVE-2019-20892P4MEDIUMCVSS 6.5fixed in net-snmp 5.8+dfsg-3 (bookworm)2019
CVE-2019-20892 [MEDIUM] CVE-2019-20892: net-snmp - net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in sn...
net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.
Scope: local
bookworm: resolved (fixed in 5.8+dfsg-3)
bullseye: resolved (fixed in 5.8+dfsg-3)
forky: res
debian
CVE-2008-6123P4LOWCVSS 5.0fixed in net-snmp 5.4.3~dfsg-1 (bookworm)2008
CVE-2008-6123 [MEDIUM] CVE-2008-6123: net-snmp - The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 thr...
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion."
Scope: local
bookworm: resolved
debian
CVE-2022-24806P4MEDIUMCVSS 6.5fixed in net-snmp 5.9.3+dfsg-1 (bookworm)2022
CVE-2022-24806 [MEDIUM] CVE-2022-24806: net-snmp - net-snmp provides various tools relating to the Simple Network Management Protoc...
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing th
debian
CVE-2014-2284P4MEDIUMCVSS 5.0fixed in net-snmp 5.7.2.1~dfsg-3 (bookworm)2014
CVE-2014-2284 [MEDIUM] CVE-2014-2284: net-snmp - The Linux implementation of the ICMP-MIB in Net-SNMP 5.5 before 5.5.2.1, 5.6.x b...
The Linux implementation of the ICMP-MIB in Net-SNMP 5.5 before 5.5.2.1, 5.6.x before 5.6.2.1, and 5.7.x before 5.7.2.1 does not properly validate input, which allows remote attackers to cause a denial of service via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 5.7.2.1~dfsg-3)
bullseye: resolved (fixed in 5.7.2.1~dfsg-3)
forky: resolved (fixed in
debian
CVE-2014-3565P4MEDIUMCVSS 5.0fixed in net-snmp 5.7.2.1~dfsg-7 (bookworm)2014
CVE-2014-3565 [MEDIUM] CVE-2014-3565: net-snmp - snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows...
snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB file, as demonstrated by a NULL type in an ifMtu trap message.
Scope: local
bookworm: resolved (fixed in 5.7.2.1~dfsg-
debian
CVE-2014-2310P4MEDIUMCVSS 4.3fixed in net-snmp 5.7.2~dfsg-3 (bookworm)2014
CVE-2014-2310 [MEDIUM] CVE-2014-2310: net-snmp - The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a ...
The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a denial of service (hang) by sending a multi-object request with an Object ID (OID) containing more subids than previous requests, a different vulnerability than CVE-2012-6151.
Scope: local
bookworm: resolved (fixed in 5.7.2~dfsg-3)
bullseye: resolved (fixed in 5.7.2~dfsg-3)
forky: resol
debian
CVE-2003-0935P4MEDIUMCVSS 6.4fixed in net-snmp 5.0.9 (bookworm)2003
CVE-2003-0935 [MEDIUM] CVE-2003-0935: net-snmp - Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, ...
Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.
Scope: local
bookworm: resolved (fixed in 5.0.9)
bullseye: resolved (fixed in 5.0.9)
forky: resolved (fixed in 5.0.9)
sid: resolved (fixed in 5.0.9)
trixie: resolved (fixed in 5.0.9)
debian
CVE-2005-2177P4LOWCVSS 5.0fixed in net-snmp 5.2.1.2-1 (bookworm)2005
CVE-2005-2177 [MEDIUM] CVE-2005-2177: net-snmp - Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp i...
Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.
Scope: local
bookworm: resolved (fixed in 5.2.1.2-1)
bullseye: resolved (fixed in 5.2.1.2-1)
forky: r
debian
CVE-2014-2285P4LOWCVSS 4.3fixed in net-snmp 5.7.2.1~dfsg-3 (bookworm)2014
CVE-2014-2285 [MEDIUM] CVE-2014-2285: net-snmp - The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP...
The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.
Scope: local
bookworm: resolved
debian
CVE-2002-1170P4MEDIUMCVSS 5.0fixed in net-snmp 5.0.6 (bookworm)2002
CVE-2002-1170 [MEDIUM] CVE-2002-1170: net-snmp - The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-...
The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.
Scope: local
bookworm: resolved (fixed in 5.0.6)
bullseye: resolved (fixed in 5.0.6)
forky: resolved (fixed in 5.0.6)
sid: resolved (fixed in 5.0.6)
debian
CVE-2012-2141P4LOWCVSS 3.5fixed in net-snmp 5.4.3~dfsg-2.5 (bookworm)2012
CVE-2012-2141 [LOW] CVE-2012-2141: net-snmp - Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/...
Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.
Scope: local
bookworm: resolved (fixed in 5.4.3~dfsg-2.5)
bullseye: resolved (fixed in 5.4.3
debian
← Previous2 / 2