First published: Fri Jun 19 2009(Updated: )
agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP GETBULK request that triggers a divide-by-zero error. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-4309.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Net-SNMP Agent Libraries | =5.0.9 | |
Red Hat Enterprise Linux | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1887 has been classified as a high-severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2009-1887, update the net-snmp package to a version that has patched this vulnerability.
CVE-2009-1887 affects net-snmp version 5.0.9 on Red Hat Enterprise Linux 3.
CVE-2009-1887 can be exploited via a crafted SNMP GETBULK request that leads to a daemon crash.
There is no official workaround for CVE-2009-1887; patching the software is the recommended solution.