CVE-2017-16820
collectd: double free in csnmp_read_table function in snmp.c
Severity Score
9.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).
La función csnmp_read_table en snmp.c en el plugin SNMP en collectd, en versiones anteriores a la 5.6.3, es susceptible a una doble liberación (double free) en un cierto caso de error, lo que podría conducir a un cierre inesperado (o, potencialmente, provocar otro impacto).
A double-free vulnerability was found in the csnmp_read_table function in the SNMP plugin of collectd. A network-based attacker could exploit this by sending malformed data, causing collectd to crash or possibly other impact.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-11-14 CVE Reserved
- 2017-11-14 CVE Published
- 2023-05-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-415: Double Free
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
https://bugs.debian.org/881757 | Issue Tracking | |
https://github.com/collectd/collectd/issues/2291 | Issue Tracking | |
https://github.com/collectd/collectd/releases/tag/collectd-5.6.3 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/collectd/collectd/commit/d16c24542b2f96a194d43a73c2e5778822b9cb47 | 2018-09-04 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2018:0252 | 2018-09-04 | |
https://access.redhat.com/errata/RHSA-2018:0299 | 2018-09-04 | |
https://access.redhat.com/errata/RHSA-2018:0560 | 2018-09-04 | |
https://access.redhat.com/errata/RHSA-2018:1605 | 2018-09-04 | |
https://access.redhat.com/errata/RHSA-2018:2615 | 2018-09-04 | |
https://security.gentoo.org/glsa/201803-10 | 2018-09-04 | |
https://access.redhat.com/security/cve/CVE-2017-16820 | 2018-09-04 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1516447 | 2018-09-04 |