First published: Thu Oct 30 2003(Updated: )
Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifindex variables, which cause snmpnetstat to write variable data past the end of an array.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
vne-snmp | <=4.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1570 is classified as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2002-1570, upgrade to a version of UCD-SNMP or net-snmp later than 4.2.3 that addresses this heap-based buffer overflow issue.
UCD-SNMP versions up to and including 4.2.3 are affected by CVE-2002-1570.
Yes, CVE-2002-1570 can be exploited remotely through multiple getnextrequest PDU messages.
CVE-2002-1570 is a heap-based buffer overflow vulnerability.