First published: Fri Oct 11 2002(Updated: )
The handle_var_requests function in snmp_agent.c for the SNMP daemon in the Net-SNMP (formerly ucd-snmp) package 5.0.1 through 5.0.5 allows remote attackers to cause a denial of service (crash) via a NULL dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Net-SNMP Agent Libraries | =5.0.4_pre2 | |
CentOS Net-SNMP Agent Libraries | =5.0.1 | |
CentOS Net-SNMP Agent Libraries | =5.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1170 is classified as a high severity vulnerability due to its potential to cause denial of service.
You can fix CVE-2002-1170 by upgrading to a version of Net-SNMP that is later than 5.0.5.
CVE-2002-1170 enables remote attackers to cause a denial of service through a NULL dereference.
Net-SNMP versions 5.0.1 through 5.0.5 are affected by CVE-2002-1170.
The vulnerability is found in the handle_var_requests function of snmp_agent.c within the Net-SNMP package.