CVE-2018-18066
Summary
| CVE | CVE-2018-18066 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-08 18:29:00 UTC |
| Updated | 2019-10-16 18:15:00 UTC |
| Description | snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| net-snmp / Code / Commit [7ffb8e] |
MISC |
sourceforge.net |
Patch, Third Party Advisory |
| October 2018 Net-SNMP Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| dumpco.re |
MISC |
dumpco.re |
Exploit, Patch, Third Party Advisory |
| net-snmp / Code / Commit [f23bcd] |
MISC |
sourceforge.net |
Patch, Third Party Advisory |
| Oracle Critical Patch Update - October 2019 |
MISC |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377511 Alibaba Cloud Linux Security Update for net-snmp (ALINUX2-SA-2020:0064)
- 591311 Bosch Rexroth PRA-ES8P2S Ethernet-Switch Multiple Vulnerabilities (BOSCH-SA-247053-BT)