Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2008-4309

Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.

  • Published: Oct 31, 2008
  • Updated: Nov 8, 2023
  • CVE: CVE-2008-4309
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
net-snmp / net-snmp 5.4 5.4.x
net-snmp / net-snmp 5.3.2.2 5.3.2.2.x
net-snmp / net-snmp 5.2.5 5.2.5.x