FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2007-5846

This CVE name corresponds to:

Entered Topic
2007-11-13 net-snmp -- denial of service via GETBULK request

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2007-5846
Phase Assigned(20071106)

Description

The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value.

References

Source Reference
BUGTRAQ 20080416 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus
MLIST [Security-announce] 20080415 VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus
MISC http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/tags/Ext-5-4-1/net-snmp/agent/snmp_agent.c?view=log
CONFIRM http://sourceforge.net/tracker/index.php?func=detail&aid=1712988&group_id=12694&atid=112694
CONFIRM http://sourceforge.net/project/shownotes.php?release_id=528095&group_id=12694
CONFIRM http://bugs.gentoo.org/show_bug.cgi?id=198346
DEBIAN DSA-1483
FEDORA FEDORA-2007-3019
GENTOO GLSA-200711-31
MANDRIVA MDKSA-2007:225
REDHAT RHSA-2007:1045
SUSE SUSE-SR:2007:025
UBUNTU USN-564-1
BID 26378
OSVDB 38904
OVAL oval:org.mitre.oval:def:11258
VUPEN ADV-2007-3802
VUPEN ADV-2008-1234
SECTRACK 1018918
SECUNIA 27558
SECUNIA 27689
SECUNIA 27685
SECUNIA 27733
SECUNIA 27740
SECUNIA 27965
SECUNIA 28413
SECUNIA 28825
SECUNIA 29785