net-snmp: numresponses calculation integer overflow in snmp_agent.c
Published Oct 31, 2008
7.5
HIGHCVSS 3.1
EPSS 4.97%
Description
Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.
Affected products
No data.
No data.
Red Hat Enterprise Linux 3
net-snmp-0:5.0.9-2.30E.25
Fixed · RHSA-2008:0971
Red Hat Enterprise Linux 4
net-snmp-0:5.1.2-13.el4_7.2
Fixed · RHSA-2008:0971
Red Hat Enterprise Linux 5
net-snmp-1:5.3.1-24.el5_2.2
Fixed · RHSA-2008:0971
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 3 | net-snmp-0:5.0.9-2.30E.25 | Fixed | RHSA-2008:0971 |
| Red Hat Enterprise Linux 4 | net-snmp-0:5.1.2-13.el4_7.2 | Fixed | RHSA-2008:0971 |
| Red Hat Enterprise Linux 5 | net-snmp-1:5.3.1-24.el5_2.2 | Fixed | RHSA-2008:0971 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed May 28, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.97% (0.04966) | 91.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.93% (0.04926) | 90.98th | v5 (v2026.06.15) |
| Jul 16, 2025 | 11.14% (0.11144) | 93.15th | v4 (v2025.03.14) |
| Mar 30, 2025 | 7.87% (0.07867) | 91.20th | v4 (v2025.03.14) |
| Mar 29, 2025 | 14.51% (0.14511) | 90.77th | v4 (v2025.03.14) |
| Mar 17, 2025 | 8.44% (0.08440) | 91.70th | v4 (v2025.03.14) |
| Dec 12, 2024 | 4.85% (0.04853) | 93.05th | v3 (v2023.03.01) |
| Mar 7, 2023 | 4.85% (0.04853) | 91.47th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Feb 13, 2023 | 4.36% (0.04358) | 87.63th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.69% (0.02686) | 82.44th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (46)
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2010//Dec/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=125017764422557&w=2 vendor-advisoryx_refsource_HP
- http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/tags/Ext-5-2-5-1/net-snmp/agent/snmp_agent.c?r1=17271&r2=17272&pathrev=17272 x_refsource_MISCVendor Advisory
- http://secunia.com/advisories/32539 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32560 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32664 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32711 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33003 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33095 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33631 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33746 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33821 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35074 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/35679 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200901-15.xml vendor-advisoryx_refsource_GENTOO
- http://sourceforge.net/forum/forum.php?forum_id=882903 x_refsource_CONFIRM
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-262908-1 vendor-advisoryx_refsource_SUNALERT
- http://support.apple.com/kb/HT3549 x_refsource_CONFIRM
- http://support.apple.com/kb/HT4298 x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2008-467.htm x_refsource_CONFIRM
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0315 x_refsource_CONFIRM
- http://www.debian.org/security/2008/dsa-1663 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:225 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2008/10/31/1 mailing-listx_refsource_MLIST
- http://www.redhat.com/support/errata/RHSA-2008-0971.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/498280/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/32020 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1021129 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/usn-685-1 vendor-advisoryx_refsource_UBUNTU
- http://www.us-cert.gov/cas/techalerts/TA09-133A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vmware.com/security/advisories/VMSA-2009-0001.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2008/2973 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/3400 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/0301 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/1297 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/1771 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-4309 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=469349 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46262 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2008-4309
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6171 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6353 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9860 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2008-4309
Change history (0)
No recorded changes yet.