CVE-2018-18065
Summary
| CVE | CVE-2018-18065 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-08 18:29:00 UTC |
| Updated | 2019-10-16 18:15:00 UTC |
| Description | _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| net-snmp / Code / Commit [7ffb8e] |
MISC |
sourceforge.net |
Patch, Third Party Advisory |
| CVE-2018-18065 Denial of Service in PAN-OS Management Interface |
CONFIRM |
security.paloaltonetworks.com |
|
| October 2018 Net-SNMP Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| dumpco.re |
MISC |
dumpco.re |
Exploit, Patch, Third Party Advisory |
| Net-SNMP CVE-2018-18065 Remote Denial of Service Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| USN-3792-3: Net-SNMP vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| cert-portal.siemens.com/productcert/pdf/ssa-978220.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| net-snmp 5.7.3 - (Authenticated) Denial of Service (PoC) - Linux dos Exploit |
EXPLOIT-DB |
www.exploit-db.com |
Exploit, Patch, Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-4314-1 net-snmp |
DEBIAN |
www.debian.org |
Third Party Advisory |
| USN-3792-1: Net-SNMP vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| USN-3792-2: Net-SNMP vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Oracle Critical Patch Update - October 2019 |
MISC |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591311 Bosch Rexroth PRA-ES8P2S Ethernet-Switch Multiple Vulnerabilities (BOSCH-SA-247053-BT)
- 751589 SUSE Enterprise Linux Security Update for net-snmp (SUSE-SU-2022:0050-1)
- 751591 OpenSUSE Security Update for net-snmp (openSUSE-SU-2022:0050-1)
- 751907 SUSE Enterprise Linux Security Update for net-snmp (SUSE-SU-2022:0050-2)