5
CVSSv2

CVE-2005-2177

Published: 11/07/2005 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Net-SNMP 5.0.x prior to 5.0.10.2, 5.2.x prior to 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote malicious users to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.

Vulnerable Product Search on Vulmon Subscribe to Product

net-snmp net-snmp 5.0.2

net-snmp net-snmp 5.0.3

net-snmp net-snmp 5.2

net-snmp net-snmp 5.2.1

net-snmp net-snmp 5.0.4_pre2

net-snmp net-snmp 5.0.5

net-snmp net-snmp 5.0.6

net-snmp net-snmp 5.0.1

net-snmp net-snmp 5.0.10

net-snmp net-snmp 5.0.9

net-snmp net-snmp 5.1.3

net-snmp net-snmp 5.0

net-snmp net-snmp 5.0.7

net-snmp net-snmp 5.0.8

Vendor Advisories

USN-190-1 fixed a vulnerability in the net-snmp library It was discovered that the same problem also affects the ucs-snmp implementation (which is used by the Cyrus email server) ...
A remote Denial of Service has been discovered in the SMNP (Simple Network Management Protocol) library If a SNMP agent uses TCP sockets for communication, a malicious SNMP server could exploit this to crash the agent Please note that by default SNMP uses UDP sockets ...
Synopsis net-snmp security update Type/Severity Security Advisory: Low Topic Updated net-snmp packages that fix two security issues and various bugsare now availableThis update has been rated as having low security impact by the Red HatSecurity Response Team Description SNMP (Simple Netwo ...
Synopsis ucd-snmp security update Type/Severity Security Advisory: Low Topic Updated ucd-snmp packages that a security issue are now available for RedHat Enterprise Linux 21This update has been rated as having low security impact by the Red HatSecurity Response Team Description SNMP (Sim ...
Synopsis net-snmp security update Type/Severity Security Advisory: Low Topic Updated net-snmp packages that fix two security issues and various bugsare now availableThis update has been rated as having low security impact by the Red HatSecurity Response Team Description SNMP (Simple Netwo ...
A security vulnerability has been found in Net-SNMP releases that could allow a denial of service attack against Net-SNMP agents that have opened a stream based protocol (eg TCP but not UDP) By default, Net-SNMP does not open a TCP port The old stable distribution (woody) does not contain a net-snmp package For the stable distribution (sarge) ...

References

CWE-20http://sourceforge.net/mailarchive/forum.php?thread_id=7659656&forum_id=12455http://www.trustix.org/errata/2005/0034/http://secunia.com/advisories/15930http://www.securityfocus.com/bid/14168http://www.ubuntu.com/usn/usn-190-1http://support.avaya.com/elmodocs2/security/ASA-2005-225.pdfhttp://www.debian.org/security/2005/dsa-873http://secunia.com/advisories/18635http://secunia.com/advisories/17217http://secunia.com/advisories/17343http://www.redhat.com/support/errata/RHSA-2005-373.htmlhttp://www.redhat.com/support/errata/RHSA-2005-395.htmlhttp://www.redhat.com/support/errata/RHSA-2005-720.htmlhttp://www.novell.com/linux/security/advisories/2005_24_sr.htmlhttp://secunia.com/advisories/17135http://secunia.com/advisories/17282http://secunia.com/advisories/16999http://secunia.com/advisories/17007http://www.vmware.com/download/esx/esx-202-200610-patch.htmlhttp://www.vmware.com/download/esx/esx-213-200610-patch.htmlhttp://www.vmware.com/download/esx/esx-254-200610-patch.htmlhttp://secunia.com/advisories/22875http://www.net-snmp.org/about/ChangeLog.htmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-102725-1http://www.securityfocus.com/bid/21256http://securitytracker.com/id?1017273http://secunia.com/advisories/23058http://secunia.com/advisories/25373http://www.mandriva.com/security/advisories?name=MDKSA-2006:025http://www.novell.com/linux/security/advisories/2007_12_sr.htmlhttp://www.novell.com/linux/security/advisories/2007_13_sr.htmlhttp://secunia.com/advisories/25432http://secunia.com/advisories/25787http://www.vupen.com/english/advisories/2007/1883http://www.vupen.com/english/advisories/2006/4502http://www.vupen.com/english/advisories/2006/4677https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9986http://www.securityfocus.com/archive/1/451426/100/200/threadedhttp://www.securityfocus.com/archive/1/451419/100/200/threadedhttp://www.securityfocus.com/archive/1/451417/100/200/threadedhttp://www.securityfocus.com/archive/1/451404/100/0/threadedhttps://nvd.nist.govhttps://usn.ubuntu.com/190-2/