#VU15321 Null pointer dereference in Net-snmp - CVE-2018-18066
Published: October 10, 2018 / Updated: October 11, 2018
Net-snmp
net-snmp.sourceforge.net
Description
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.
The vulnerability exists in the snmp_oid_compare() function, as defined in the snmplib/snmp_api.c source code file due to a NULL pointer exception bug. A remote attacker can send a malicious UDP packet, trigger a NULL pointer dereference condition, cause the application to crash.