CVE-2005-2177: Input Validation
Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2177?
CVE-2005-2177 has a severity rating indicating it allows remote attackers to cause a denial of service through a TCP packet manipulation.
How do I fix CVE-2005-2177?
To fix CVE-2005-2177, upgrade Net-SNMP to version 5.0.10.2 or later, or 5.2.1.2 or later.
Which versions of Net-SNMP are affected by CVE-2005-2177?
Versions of Net-SNMP affected by CVE-2005-2177 include 5.0.x before 5.0.10.2, 5.1.3, and 5.2.x before 5.2.1.2.
What type of attack does CVE-2005-2177 exploit?
CVE-2005-2177 exploits an infinite loop triggered by a specially crafted TCP packet, leading to daemon hang and high CPU consumption.
Can CVE-2005-2177 be exploited remotely?
Yes, CVE-2005-2177 can be exploited remotely by attackers sending a specific TCP packet to the vulnerable Net-SNMP service.