net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who must use SNMPv1 or SNMPv2c should use a complex community string and enhance the protection by restricting access to a given IP address range.
References
Configurations
History
11 Feb 2025, 21:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/net-snmp/net-snmp/commit/ce66eb97c17aa9a48bc079be7b65895266fa6775 - Release Notes |
10 Feb 2025, 19:05
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:net-snmp:net-snmp:*:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
|
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2103225 - Issue Tracking | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2105241 - Issue Tracking | |
References | () https://github.com/net-snmp/net-snmp/commit/ce66eb97c17aa9a48bc079be7b65895266fa6775 - Patch | |
References | () https://lists.debian.org/debian-lts-announce/2022/08/msg00020.html - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FX75KKGMO5XMV6JMQZF6KOG3JPFNQBY7/ - Mailing List, Product | |
References | () https://security.gentoo.org/glsa/202210-29 - Third Party Advisory | |
References | () https://www.debian.org/security/2022/dsa-5209 - Mailing List, Third Party Advisory | |
First Time |
Debian debian Linux
Net-snmp net-snmp Debian Fedoraproject fedora Fedoraproject Net-snmp |
Information
Published : 2024-04-16 20:15
Updated : 2025-02-11 21:56
NVD link : CVE-2022-24810
Mitre link : CVE-2022-24810
CVE.ORG link : CVE-2022-24810
JSON object : View
Products Affected
net-snmp
- net-snmp
debian
- debian_linux
fedoraproject
- fedora
CWE
CWE-476
NULL Pointer Dereference