Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2015-5621

Published: 31 July 2015

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

Priority

Medium

Status

Package Release Status
net-snmp
Launchpad, Ubuntu, Debian
precise
Released (5.4.3~dfsg-2.4ubuntu1.3)
trusty
Released (5.7.2~dfsg-8.1ubuntu3.1)
upstream Needed

vivid
Released (5.7.2~dfsg-8.1ubuntu5.1)
Patches:
upstream: http://sourceforge.net/p/net-snmp/code/ci/f23bcd3ac6ddee5d0a48f9703007ccc738914791/