Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DSA-1663-1 | New net-snmp packages fix several vulnerabilities |
![]() |
USN-685-1 | Net-SNMP vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T10:08:35.116Z
Reserved: 2008-09-29T00:00:00
Link: CVE-2008-4309

No data.

Status : Deferred
Published: 2008-10-31T20:29:09.497
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-4309


No data.