Back

HIGH

net-snmp: numresponses calculation integer overflow in snmp_agent.c

Published Oct 31, 2008

Description

Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (46)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 31, 2008
Updated May 28, 2026
Reserved Sep 29, 2008
CISA Vulnrichment
Updated May 28, 2026
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Oct 31, 2008