Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of service (crash or infinite loop, CPU consumption, and hang) by causing the AgentX subagent to timeout.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/64048 | vdb entry exploit |
http://lists.apple.com/archives/security-announce/2015/Oct/msg00005.html | vendor advisory |
https://support.apple.com/HT205375 | |
http://sourceforge.net/p/net-snmp/bugs/2411/ | exploit |
https://rhn.redhat.com/errata/RHSA-2014-0322.html | vendor advisory |
http://seclists.org/oss-sec/2013/q4/415 | mailing list |
http://seclists.org/oss-sec/2013/q4/398 | mailing list |
http://www.ubuntu.com/usn/USN-2166-1 | vendor advisory |
http://secunia.com/advisories/59974 | third party advisory |
http://secunia.com/advisories/57870 | third party advisory |
http://www.gentoo.org/security/en/glsa/glsa-201409-02.xml | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/89485 | vdb entry |
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 | |
http://secunia.com/advisories/55804 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1038007 |