SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
Link | Tags |
---|---|
https://security.gentoo.org/glsa/202007-63 | third party advisory vendor advisory |
http://www.snmptt.org/changelog.shtml | release notes vendor advisory |
https://lists.debian.org/debian-lts-announce/2020/10/msg00006.html | third party advisory mailing list |