Net-SNMP CVE-2018-1000116 Remote Code Execution Vulnerability
BID:104692
Info
Net-SNMP CVE-2018-1000116 Remote Code Execution Vulnerability
| Bugtraq ID: | 104692 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-1000116 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2018 12:00AM |
| Updated: | Mar 07 2018 12:00AM |
| Credit: | Robert Story |
| Vulnerable: |
Redhat Enterprise Linux Workstation 7 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server from RHUI 7 Redhat Enterprise Linux Server from RHUI 6 Redhat Enterprise Linux Server - Update Services for SAP Solutions 7.4 Redhat Enterprise Linux Server - Update Services for SAP Solutions 7.3 Redhat Enterprise Linux Server - Update Services for SAP Solutions 7.2 Redhat Enterprise Linux Server - TUS 7.3 Redhat Enterprise Linux Server - Extended Update Support from RHUI 6.7 Redhat Enterprise Linux Server - Extended Update Support 7.5 Redhat Enterprise Linux Server - Extended Update Support 7.4 Redhat Enterprise Linux Server - Extended Update Support 7.3 Redhat Enterprise Linux Server - Extended Update Support 7.2 Redhat Enterprise Linux Server - Extended Update Support 7.1 Redhat Enterprise Linux Server - Extended Update Support 6.7 Redhat Enterprise Linux Server - AUS 7.4 Redhat Enterprise Linux Server - AUS 7.3 Redhat Enterprise Linux Server (for IBM Power LE) - Update Services for SAP Solutions 7. Redhat Enterprise Linux Server (for IBM Power LE) - Update Services for SAP Solutions 7. Redhat Enterprise Linux Server 7 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux for Scientific Computing 7 Redhat Enterprise Linux for Scientific Computing 6 Redhat Enterprise Linux for Power, little endian - Extended Update Supp 7.5 Redhat Enterprise Linux for Power, little endian - Extended Update Supp 7.4 Redhat Enterprise Linux for Power, little endian - Extended Update Supp 7.3 Redhat Enterprise Linux for Power, little endian - Extended Update Supp 7.2 Redhat Enterprise Linux for Power, little endian - Extended Update Supp 7.1 Redhat Enterprise Linux for Power, little endian 7 Redhat Enterprise Linux for Power, big endian - Extended Update Support 7.5 Redhat Enterprise Linux for Power, big endian - Extended Update Support 7.4 Redhat Enterprise Linux for Power, big endian - Extended Update Support 7.3 Redhat Enterprise Linux for Power, big endian - Extended Update Support 7.2 Redhat Enterprise Linux for Power, big endian - Extended Update Support 6.7 Redhat Enterprise Linux for Power, big endian 7 Redhat Enterprise Linux for Power, big endian 6 Redhat Enterprise Linux for IBM z Systems - Extended Update Support 7.5 Redhat Enterprise Linux for IBM z Systems - Extended Update Support 7.4 Redhat Enterprise Linux for IBM z Systems - Extended Update Support 7.3 Redhat Enterprise Linux for IBM z Systems - Extended Update Support 7.2 Redhat Enterprise Linux for IBM z Systems - Extended Update Support 7.1 Redhat Enterprise Linux for IBM z Systems - Extended Update Support 6.7 Redhat Enterprise Linux for IBM z Systems 7 Redhat Enterprise Linux for IBM z Systems 6 Redhat Enterprise Linux EUS Compute Node 7.5 Redhat Enterprise Linux EUS Compute Node 7.4 Redhat Enterprise Linux EUS Compute Node 7.3 Redhat Enterprise Linux EUS Compute Node 7.2 Redhat Enterprise Linux EUS Compute Node 7.1 Redhat Enterprise Linux EUS Compute Node 6.7 Redhat Enterprise Linux Desktop 7 Redhat Enterprise Linux Desktop 6 Net-SNMP Net-SNMP 5.7.2 |
| Not Vulnerable: | |
Exploit / POC
Net-SNMP CVE-2018-1000116 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: http://.
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: http://.
Solution / Fix
Net-SNMP CVE-2018-1000116 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Net-SNMP CVE-2018-1000116 Remote Code Execution Vulnerability
References:
References:
- Net-SNMP Homepage (Net-SNMP)
- #2821 NET-SNMP Heap Corruption (Sourceforge)
- Bug 1552844 CVE-2018-1000116 net-snmp: Heap corruption in snmp_pdu_parse (Redhat)
- CHANGES: BUG: #2615: Don't return incompletely parsed varbinds (Sourceforge)
- CVE-2018-1000116 (Redhat)
- RHSA-2015:1636 - Security Advisory (Redhat)