CVE-2002-1170: Medium severity Net-SNMP Net-SNMP vulnerability
Published Oct 11, 2002
·Updated
The handlevarrequests function in snmpagent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.
Affected Software
3 affected components
Net-SNMP Net-SNMP=5.0.4_pre2
Net-SNMP Net-SNMP=5.0.1
Net-SNMP Net-SNMP=5.0.3
Remediation
Patch Available
Event History
Oct 11, 2002
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1170?
CVE-2002-1170 is classified as a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2002-1170?
You can fix CVE-2002-1170 by upgrading to a version of Net-SNMP that is later than 5.0.5.
3
What type of attack does CVE-2002-1170 enable?
CVE-2002-1170 enables remote attackers to cause a denial of service through a NULL dereference.
4
Which versions of Net-SNMP are affected by CVE-2002-1170?
Net-SNMP versions 5.0.1 through 5.0.5 are affected by CVE-2002-1170.
5
What component is compromised in CVE-2002-1170?
The vulnerability is found in the handle_var_requests function of snmp_agent.c within the Net-SNMP package.