CMU SNMP SNMPTRAPD Daemon Remote Format String Vulnerability
BID:16267
Info
CMU SNMP SNMPTRAPD Daemon Remote Format String Vulnerability
| Bugtraq ID: | 16267 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2006 12:00AM |
| Updated: | Jan 16 2006 12:00AM |
| Credit: | Seregorn <[email protected]> discovered this issue. |
| Vulnerable: |
Carnegie Mellon University CMU SNMP 3.7 Carnegie Mellon University CMU SNMP 3.6 |
| Not Vulnerable: | |
Discussion
CMU SNMP SNMPTRAPD Daemon Remote Format String Vulnerability
A remote format string vulnerability affects the CMU SNMP's snmptrapd daemon. This issue is due to a failure of the application to properly sanitize user-supplied input data prior to using it in a formatted-printing function.
A remote attacker may leverage this issue to execute arbitrary code with superuser privileges, facilitating the complete compromise of affected computers.
It should be noted that CMU SNMP has not been actively maintained for several years.
A remote format string vulnerability affects the CMU SNMP's snmptrapd daemon. This issue is due to a failure of the application to properly sanitize user-supplied input data prior to using it in a formatted-printing function.
A remote attacker may leverage this issue to execute arbitrary code with superuser privileges, facilitating the complete compromise of affected computers.
It should be noted that CMU SNMP has not been actively maintained for several years.
Exploit / POC
CMU SNMP SNMPTRAPD Daemon Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
CMU SNMP SNMPTRAPD Daemon Remote Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
CMU SNMP SNMPTRAPD Daemon Remote Format String Vulnerability
References:
References:
- Linux CMU SNMP Project Home Page (Carnegie Mellon University)
- Digital Armaments Security Advisory 01.16.2006: CMU SNMP utilities snmptrad For ([email protected])