Double Free Vulnerability in Net-SNMP Affecting Multiple Linux Distributions
CVE-2019-20892

6.5MEDIUM

Key Information:

Vendor

Net-snmp

Status
Vendor
CVE Published:
25 June 2020

What is CVE-2019-20892?

The vulnerability in Net-SNMP prior to version 5.8.1.pre1 arises from a double free issue within the usm_free_usmStateReference function during handling of SNMPv3 GetBulk requests. This flaw can lead to potential exploitation impacting the stability and functioning of the software across various Linux distributions utilizing the affected net-snmp packages. Users and system administrators are advised to upgrade their Net-SNMP installations to ensure that the software operates securely and effectively.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.