CVE-2018-1000116: Critical severity F5 BIG-IQ Centralized Management vulnerability
Published Mar 7, 2018
·Updated
NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.
Affected Software
4 affected componentsFixes available
debian/net-snmp
5.7.3+dfsg-5+deb10u25.7.3+dfsg-5+deb10u45.9+dfsg-4+deb11u15.9.3+dfsg-25.9.4+dfsg-1
F5 BIG-IQ Centralized Management>=8.2.0<=8.3.0
Net-SNMP Net-SNMP=5.7.2
Debian Debian Linux=7.0
Event History
Mar 7, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Mar 26, 2018
Data Sourced
02:12 PM
SeverityAffected Software
Mar 24, 2025
Advisory Published
via F5·03:45 PM
Frequently Asked Questions
1
What is CVE-2018-1000116?
CVE-2018-1000116 is a heap corruption vulnerability in the UDP protocol handler of NET-SNMP version 5.7.2 that can lead to command execution.
2
What is the severity of CVE-2018-1000116?
CVE-2018-1000116 has a severity rating of 9.8, which is considered critical.
3
How does CVE-2018-1000116 affect NET-SNMP?
CVE-2018-1000116 affects NET-SNMP version 5.7.2, potentially allowing for command execution.
4
What versions of NET-SNMP are affected by CVE-2018-1000116?
NET-SNMP version 5.7.2 is affected by CVE-2018-1000116.
5
How can I fix CVE-2018-1000116?
To fix CVE-2018-1000116, update to NET-SNMP version 5.7.3+dfsg-5+deb10u2, 5.7.3+dfsg-5+deb10u4, 5.9+dfsg-4+deb11u1, 5.9.3+dfsg-2, or 5.9.4+dfsg-1.