« List of all CVEs

CVE-2008-4309

Published: 10/31/2008 Last updated: 8/7/2024 Reserved: 9/29/2008

Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (2)

conf-netsnmp netsnmp

Products affected (1)

Product Vendor Version
n/a n/a all firmware versions

References (86)