CLA-2003:696Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000696 CVE-2002-1570
Net-SNMP 4.2.3 - snmpnetstat Remote Heap Overflow
Record summary
CVE-2002-1570 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifindex variables, which cause snmpnetstat to write variable data past the end of an array.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNet-SNMP 4.2.3 - snmpnetstat Remote Heap OverflowExploitDB exploitby Juan M. de la TorreNot analyzed1 file
References
520020103 Heap overflow in snmpnetstatmailing list
http://www.securityfocus.com/archive/1/248141 3780vdb entry
http://www.securityfocus.com/bid/3780 netsnmp-snmpnetstat-heap-overflow(7776)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/7776 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1570