SunATM Agent SNMP Request Handling Vulnerability
BID:4732
Info
SunATM Agent SNMP Request Handling Vulnerability
| Bugtraq ID: | 4732 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 13 2002 12:00AM |
| Updated: | May 13 2002 12:00AM |
| Credit: | Vulnerability discovery first reported in the Sun patch list. |
| Vulnerable: |
Sun SunATM 5.0 Sun SunATM 4.0.1 Sun SunATM 3.0.1 Sun SunATM 2.1 |
| Not Vulnerable: | |
Discussion
SunATM Agent SNMP Request Handling Vulnerability
The SunATM SNMP agent suffers from a vulnerability related to the handling of SNMP requests. It is possible to crash the service by transmitting to it a maliciously constructed SNMPv1 request PDU.
The resultant crash may be due to a buffer overflow condition. If this is the case, attackers may be able to exploit this vulnerability to execute arbitrary code.
The SunATM SNMP agent suffers from a vulnerability related to the handling of SNMP requests. It is possible to crash the service by transmitting to it a maliciously constructed SNMPv1 request PDU.
The resultant crash may be due to a buffer overflow condition. If this is the case, attackers may be able to exploit this vulnerability to execute arbitrary code.
Exploit / POC
SunATM Agent SNMP Request Handling Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SunATM Agent SNMP Request Handling Vulnerability
Solution:
Sun has released patches:
Sun SunATM 4.0.1
Sun SunATM 5.0
Solution:
Sun has released patches:
Sun SunATM 4.0.1
Sun SunATM 5.0