First published: Tue Nov 14 2017(Updated: )
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/collectd | <=5.7.2-2<=5.7.1-1.1 | |
redhat/collectd | <5.8.0 | 5.8.0 |
redhat/collectd | <5.6.3 | 5.6.3 |
debian/collectd | 5.12.0-7 5.12.0-14 5.12.0-22 | |
collectd | <5.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16820 has a medium severity level as it can lead to a crash of the application.
To fix CVE-2017-16820, upgrade to collectd version 5.8.0 or later.
CVE-2017-16820 affects collectd versions prior to 5.6.3 and versions 5.7.2 or lower.
CVE-2017-16820 may not directly cause data loss, but it can lead to application instability which could impact data collection.
CVE-2017-16820 is not considered exploitable remotely as it requires access to the application itself.