UCD-SNMPD Command Line Parsing Local Buffer Overflow Vulnerability
BID:10396
Info
UCD-SNMPD Command Line Parsing Local Buffer Overflow Vulnerability
| Bugtraq ID: | 10396 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 21 2004 12:00AM |
| Updated: | May 21 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "priest priest" <[email protected]>. |
| Vulnerable: |
UCD-SNMP UCD-SNMP 4.2.6 |
| Not Vulnerable: | |
Discussion
UCD-SNMPD Command Line Parsing Local Buffer Overflow Vulnerability
It is reported that the UCD-SNMP 'snmpd' daemon is prone to a command line parsing buffer overflow vulnerability. This issue is due to a failure of the application to properly validate the size of user-supplied argument strings before copying them into a finite buffer. This issue may permit a local attacker to influence execution flow of the affected snmpd daemon, and ultimately execute arbitrary instructions in the context of the process.
This vulnerability is reported to affect UCD-SNMP versions up to an including version 4.2.6.
It is reported that the UCD-SNMP 'snmpd' daemon is prone to a command line parsing buffer overflow vulnerability. This issue is due to a failure of the application to properly validate the size of user-supplied argument strings before copying them into a finite buffer. This issue may permit a local attacker to influence execution flow of the affected snmpd daemon, and ultimately execute arbitrary instructions in the context of the process.
This vulnerability is reported to affect UCD-SNMP versions up to an including version 4.2.6.
Exploit / POC
UCD-SNMPD Command Line Parsing Local Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
UCD-SNMPD Command Line Parsing Local Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
UCD-SNMPD Command Line Parsing Local Buffer Overflow Vulnerability
References:
References:
- UCD-SNMP Homepage (UCD-SNMP)