Null pointer dereference in Net-snmp - CVE-2018-18065
Published: October 11, 2018
Vulnerability details
The vulnerability allows a remote authenticated attacker to cause DoS condition on the target system.
The vulnerability exists in the _set_key() function, as defined in the agent/helpers/table_container.c source code file due to a NULL pointer exception bug. A remote attacker can send a malicious UDP packet, trigger a NULL pointer dereference condition, cause the application to crash.
Affected software
Arch Linux
Debian Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Opensuse
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
Fedora
TIM 1531 IRC
SIMATIC CP 1628
SIMATIC CP 1623
SCALANCE S627-2M
SCALANCE S623
SCALANCE S612
SCALANCE S602
Chassis Management Controller (CMC) Firmware
SIMATIC CP443-1 OPC UA
SIMATIC CP 443-1 Advanced
SIMATIC CP 443-1 Standard
SIMATIC CP 343-1 Advanced
SIMATIC CP 1626
IE/PB LINK PN IO
SUSE Linux Enterprise Module for Packagehub Subpackages
libsnmp30-debuginfo
snmp-mibs
perl-SNMP-debuginfo
perl-SNMP
net-snmp-devel
net-snmp-debugsource
net-snmp-debuginfo
net-snmp
libsnmp30
libsnmp30-32bit-debuginfo
libsnmp30-32bit
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
EMC Cloud Tiering Appliance
How to mitigate CVE-2018-18065
SIMATIC CP 1628 - update to 14.00.15.00_51.25.00.01
SIMATIC CP 1623 - update to 14.00.15.00_51.25.00.01
Chassis Management Controller (CMC) Firmware - addressed in versions 2.41.200.202503050519, 3.42.200.202503050519
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
libsnmp30-debuginfo - update to 5.7.3-10.9.1
snmp-mibs - update to 5.7.3-10.9.1
perl-SNMP-debuginfo - update to 5.7.3-10.9.1
perl-SNMP - update to 5.7.3-10.9.1
net-snmp-devel - update to 5.7.3-10.9.1
net-snmp-debugsource - update to 5.7.3-10.9.1
net-snmp-debuginfo - update to 5.7.3-10.9.1
net-snmp - update to 5.7.3-10.9.1
libsnmp30 - update to 5.7.3-10.9.1
libsnmp30-32bit-debuginfo - update to 5.7.3-10.9.1
libsnmp30-32bit - update to 5.7.3-10.9.1
net-snmp - addressed in versions 5.8-3.fc28, 5.8-3.fc29
EMC Cloud Tiering Appliance - update to 12.1.0.65
External References
Related Security Bulletins
- Denial of service vulnerabilities in Net-snmp
- Debian update for net-snmp
- Arch Linux update for net-snmp
- OpenSUSE Linux update for net-snmp
- OpenSUSE Linux update for net-snmp
- Multiple vulnerabilities in Siemens Industrial Products
- SUSE update for net-snmp
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance Family
- SUSE update for net-snmp
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Multiple vulnerabilities in Dell Chassis Management Controller (CMC) Firmware for Dell PowerEdge FX2 and VRTX
- Fedora 28 update for net-snmp
- Fedora 29 update for net-snmp