NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.debian.org/security/2018/dsa-4154 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2018/03/msg00020.html | third party advisory mailing list |
https://sourceforge.net/p/net-snmp/bugs/2821/ | third party advisory exploit |