Array Index Error in Net-SNMP Leads to Denial of Service Vulnerability
CVE-2012-2141

Currently unrated

Key Information:

Vendor

Net-snmp

Status
Vendor
CVE Published:
14 August 2012

What is CVE-2012-2141?

The vulnerability in Net-SNMP version 5.7.1 arises from an array index error in the handle_nsExtendOutput2Table function. This defect allows remote authenticated users to execute a denial of service attack by sending an SNMP GET request for entries not present in the extension table, leading to an out-of-bounds read and crashing the snmpd process. This error can disrupt service and potentially expose sensitive information, creating significant security concerns for users relying on SNMP for network management.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.