~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
Candidate: CVE-2008-4309
PublicDate: 2008-10-31
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4309
 http://www.ubuntu.com/usn/usn-685-1
Description:
 Integer overflow in the netsnmp_create_subtree_cache function in
 agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and
 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service
 (crash) via a crafted SNMP GETBULK request, which triggers a heap-based
 buffer overflow,  related to the number of responses or repeats.
Ubuntu-Description:
Notes:
Bugs:
Priority: medium
Discovered-by:
Assigned-to: kees

Patches_net-snmp:
upstream_net-snmp: needs-triage
dapper_net-snmp: released (5.2.1.2-4ubuntu2.3)
gutsy_net-snmp: released (5.3.1-6ubuntu2.2)
hardy_net-snmp: released (5.4.1~dfsg-4ubuntu4.2)
intrepid_net-snmp: released (5.4.1~dfsg-7.1ubuntu6.1)
devel_net-snmp: not-affected