rpm package
opensuse/net-snmp&distro=openSUSE Leap 15.3
pkg:rpm/opensuse/net-snmp&distro=openSUSE%20Leap%2015.3
Vulnerabilities (8)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-24810 | — | < 5.9.3-150300.15.3.1 | 5.9.3-150300.15.3.1 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users shou | ||
| CVE-2022-24809 | — | < 5.9.3-150300.15.3.1 | 5.9.3-150300.15.3.1 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Us | ||
| CVE-2022-24808 | — | < 5.9.3-150300.15.3.1 | 5.9.3-150300.15.3.1 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contain | ||
| CVE-2022-24807 | — | < 5.9.3-150300.15.3.1 | 5.9.3-150300.15.3.1 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the | ||
| CVE-2022-24806 | — | < 5.9.3-150300.15.3.1 | 5.9.3-150300.15.3.1 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5. | ||
| CVE-2022-24805 | — | < 5.9.3-150300.15.3.1 | 5.9.3-150300.15.3.1 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit | ||
| CVE-2020-15862 | — | < 5.7.3-10.9.1 | 5.7.3-10.9.1 | Aug 19, 2020 | Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root. | ||
| CVE-2018-18065 | Med | 6.5 | < 5.7.3-10.9.1 | 5.7.3-10.9.1 | Oct 8, 2018 | _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. |
- CVE-2022-24810Apr 16, 2024affected < 5.9.3-150300.15.3.1fixed 5.9.3-150300.15.3.1
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users shou
- CVE-2022-24809Apr 16, 2024affected < 5.9.3-150300.15.3.1fixed 5.9.3-150300.15.3.1
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Us
- CVE-2022-24808Apr 16, 2024affected < 5.9.3-150300.15.3.1fixed 5.9.3-150300.15.3.1
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contain
- CVE-2022-24807Apr 16, 2024affected < 5.9.3-150300.15.3.1fixed 5.9.3-150300.15.3.1
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the
- CVE-2022-24806Apr 16, 2024affected < 5.9.3-150300.15.3.1fixed 5.9.3-150300.15.3.1
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.
- CVE-2022-24805Apr 16, 2024affected < 5.9.3-150300.15.3.1fixed 5.9.3-150300.15.3.1
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit
- CVE-2020-15862Aug 19, 2020affected < 5.7.3-10.9.1fixed 5.7.3-10.9.1
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
- affected < 5.7.3-10.9.1fixed 5.7.3-10.9.1
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.