CVE-2008-2292: Buffer Overflow
Published May 18, 2008
·Updated
Buffer overflow in the snprintvalue function in snmpget in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large OCTETSTRING in an attribute value pair (AVP).
Affected Software
3 affected components
Net-SNMP Net-SNMP=5.1.4
Net-SNMP Net-SNMP=5.2.4
Net-SNMP Net-SNMP=5.4.1
Event History
May 18, 2008
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2292?
CVE-2008-2292 has a moderate severity rating as it allows remote attackers to cause a denial of service and potentially execute arbitrary code.
2
How do I fix CVE-2008-2292?
To fix CVE-2008-2292, upgrade to a patched version of Net-SNMP beyond 5.4.1.
3
What versions of Net-SNMP are affected by CVE-2008-2292?
CVE-2008-2292 affects Net-SNMP versions 5.1.4, 5.2.4, and 5.4.1.
4
What type of vulnerability is CVE-2008-2292?
CVE-2008-2292 is a buffer overflow vulnerability in the __snprint_value function.
5
Can CVE-2008-2292 lead to code execution?
Yes, CVE-2008-2292 can potentially allow attackers to execute arbitrary code.