6.5
CVE-2022-24807
- EPSS 1.01%
- Veröffentlicht 16.04.2024 20:15:08
- Zuletzt bearbeitet 17.01.2025 16:15:01
- Erkennungen
net-snmp: A malformed OID in a SET request to SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable can cause an out-of-bounds memory access
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the issue. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who must use SNMPv1 or SNMPv2c should use a complex community string and enhance the protection by restricting access to a given IP address range.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 36
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Eus Version 9.2
Redhat ≫ Enterprise Linux Eus Version 9.4
Redhat ≫ Enterprise Linux For Arm 64 Version 9.0
Redhat ≫ Enterprise Linux For Arm 64 Version 9.2_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Version 9.4_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 9.4_aarch64
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.0
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.2_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.4_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 9.4_s390x
Redhat ≫ Enterprise Linux For Power Little Endian Version 9.0
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 9.2_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 9.4_ppc64le
Redhat ≫ Enterprise Linux Server Aus Version 9.2
Redhat ≫ Enterprise Linux Server Aus Version 9.4
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 9.2_ppc64le
Redhat ≫ Enterprise Linux Update Services For Sap Solutions Version 9.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.01% | 0.585 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| security-advisories@github.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
https://bugzilla.redhat.com/show_bug.cgi?id=2103225
https://github.com/net-snmp/net-snmp/commit/67ebb43e9038b2dae6e74ae8838b36fcc10fc937
https://github.com/net-snmp/net-snmp/commit/ce66eb97c17aa9a48bc079be7b65895266fa6775
https://lists.debian.org/debian-lts-announce/2022/08/msg00020.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FX75KKGMO5XMV6JMQZF6KOG3JPFNQBY7/
https://security.gentoo.org/glsa/202210-29
https://www.debian.org/security/2022/dsa-5209
https://bugzilla.redhat.com/show_bug.cgi?id=2105239