Logo
componentnetsnmp
Name
netsnmp
Version
5.9.3
Type
library
Description
-
Licenses
Various BSD-like
PURL
-
CPE
cpe:2.3:a:net-snmp:net-snmp:5.9.3:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
5.9.5.2

Patches#


#
Title
Author
Resolve
1
snmp_agent: disallow SET with NULL varbind
Bill Fenner <fenner@gmail.com>
CVE-2022-44792
CVE-2022-44793
2
Add Linux 6.7 compatibility parsing /proc/net/snmp
Philippe Troin <phil+github-commits@fifi.org>
3
snmptrapd: Fix out-of-bounds trapOid[] accesses
Bart Van Assche <bvanassche@acm.org>
CVE-2025-68615

Vulnerabilities#


Name
Analysis
Description
Patched
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
Patched
handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
Patched
handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.