Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Net-SNMP snmpnetstat Remote Heap Overflow Vulnerability

Net-SNMP is a package of software tools related to the Simple Network Management Protocol. One of the tools included is snmpnetstat, which can be used to retrieve and display a variety of information about a remote SNMP host.

A heap overflow vulnerability exists in the snmpnetstat client. A SNMP host may return malicious information when a list of interfaces is requested. Under some circumstances, this will result in a heap overflow in the SNMP client. Exploitation of this vulnerability can result in the execution of abritary code as the snmpnetstat client.

Earlier versions of Net-SNMP may also be vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus