CVE-2012-2141
net-snmp: Array index error, leading to out-of heap-based buffer read (snmpd crash)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.
Error de índice de array en la función nsExtendOutput2Table en agent/mibgroup/agent/extend.c en Net-SNMP v5.7.1 permite a usuarios remotos autenticados provocar una denegación de servicio (lectura fuera de límites y fallo de snmpd) a través de una petición SNMP GET para una entrada que no está en la tabla de extensiones.
The net-snmp packages provide various libraries and tools for the Simple Network Management Protocol, including an SNMP library, an extensible agent, tools for requesting or setting information from SNMP agents, tools for generating and handling SNMP traps, a version of the netstat command which uses SNMP, and a Tk/Perl Management Information Base browser. An array index error, leading to an out-of-bounds buffer read flaw, was found in the way the net-snmp agent looked up entries in the extension table. A remote attacker with read privileges to a Management Information Base subtree handled by the "extend" directive could use this flaw to crash snmpd via a crafted SNMP GET request.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-04-04 CVE Reserved
- 2012-05-24 CVE Published
- 2024-08-06 CVE Updated
- 2025-06-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/59974 | Third Party Advisory | |
http://support.citrix.com/article/CTX139049 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2012/04/26/2 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2012/04/26/3 | Mailing List |
|
http://www.securityfocus.com/bid/53255 | Vdb Entry | |
http://www.securityfocus.com/bid/53258 | Vdb Entry | |
http://www.securitytracker.com/id?1026984 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/75169 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-0124.html | 2017-08-29 | |
http://secunia.com/advisories/48938 | 2017-08-29 | |
http://www.gentoo.org/security/en/glsa/glsa-201409-02.xml | 2017-08-29 | |
https://bugzilla.redhat.com/show_bug.cgi?id=815813 | 2013-01-08 | |
https://access.redhat.com/security/cve/CVE-2012-2141 | 2013-01-08 |