NULL pointer dereference in Net-snmp - CVE-2022-44792

 

NULL pointer dereference in Net-snmp - CVE-2022-44792

Published: January 10, 2023 / Updated: May 1, 2023


Vulnerability identifier: #VU70878
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-44792
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error within the handle_ipDefaultTTL() function in agent/mibgroup/ip-mib/ip_scalars.c. A remote non-authenticated attacker can send specially crafted UDP to the application and perform a denial of service (DoS) attack.


Affected software

Net-snmp
Oracle Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Oracle Solaris
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
RecoverPoint for Virtual Machines
LANTIME Operating System Firmware (LTOS)
SUSE Linux Enterprise Module for Packagehub Subpackages
snmpd (Ubuntu package)
libsnmp30 (Ubuntu package)
snmp (Ubuntu package)
snmp-mibs
libsnmp30-debuginfo-32bit
libsnmp30-32bit
perl-SNMP-debuginfo
perl-SNMP
net-snmp
libsnmp30
net-snmp-devel
net-snmp-debugsource
net-snmp-debuginfo
libsnmp30-debuginfo
libsnmp35 (Ubuntu package)
net-snmp (Red Hat package)
net-snmp-agent-libs
net-snmp-libs
net-snmp-perl
net-snmp-utils
net-snmp-doc
libsnmp40 (Ubuntu package)
python3-net-snmp-debuginfo
libsnmp40-32bit-debuginfo
libsnmp40-32bit
python3-net-snmp
libsnmp40
libsnmp40-debuginfo
net-snmp-devel-32bit
net-snmp-help
net-snmp-gui
Tanzu Greenplum for Kubernetes
Dell EMC Streaming Data Platform
Enterprise SONiC
SIMATIC MV500
RecoverPoint for VMs
RSA Authentication Manager
IBM Security Verify Governance

How to mitigate CVE-2022-44792

Install update from vendor's website.

RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
LANTIME Operating System Firmware (LTOS) - update to 7.06.014
snmpd (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 5.7.3+dfsg-1.8ubuntu3.8, 5.8+dfsg-2ubuntu2.6, 5.9.1+dfsg-1ubuntu2.4, 5.9.3+dfsg-1ubuntu1.2
libsnmp30 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 5.7.3+dfsg-1.8ubuntu3.8
snmp (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 5.7.3+dfsg-1.8ubuntu3.8, 5.8+dfsg-2ubuntu2.6, 5.9.1+dfsg-1ubuntu2.4, 5.9.3+dfsg-1ubuntu1.2
Tanzu Greenplum for Kubernetes - update to 1.4.0
Dell EMC Streaming Data Platform - update to 1.7.0
SIMATIC MV500 - update to 3.3.5
Enterprise SONiC - update to 4.1.4
snmp-mibs - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
libsnmp30-debuginfo-32bit - update to 5.7.3-11.6.1
libsnmp30-32bit - update to 5.7.3-11.6.1
perl-SNMP-debuginfo - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
perl-SNMP - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
net-snmp - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
libsnmp30 - update to 5.7.3-11.6.1
net-snmp-devel - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
net-snmp-debugsource - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
net-snmp-debuginfo - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
libsnmp30-debuginfo - update to 5.7.3-11.6.1
libsnmp35 (Ubuntu package) - update to 5.8+dfsg-2ubuntu2.6
net-snmp (Red Hat package) - addressed in versions 5.8-27.el8, 5.9.1-9.el9
net-snmp-agent-libs - update to 5.8-27.0.1
net-snmp - update to 5.8-27.0.1
net-snmp-devel - update to 5.8-27.0.1
net-snmp-libs - update to 5.8-27.0.1
net-snmp-perl - update to 5.8-27.0.1
net-snmp-utils - update to 5.8-27.0.1
net-snmp-doc - update to 5.8-27.0.1
libsnmp40 (Ubuntu package) - addressed in versions 5.9.1+dfsg-1ubuntu2.4, 5.9.3+dfsg-1ubuntu1.2
python3-net-snmp-debuginfo - update to 5.9.3-150300.15.8.1
libsnmp40-32bit-debuginfo - update to 5.9.3-150300.15.8.1
libsnmp40-32bit - update to 5.9.3-150300.15.8.1
python3-net-snmp - update to 5.9.3-150300.15.8.1
libsnmp40 - update to 5.9.3-150300.15.8.1
libsnmp40-debuginfo - update to 5.9.3-150300.15.8.1
net-snmp-devel-32bit - update to 5.9.3-150300.15.8.1
net-snmp-help - update to 5.9-8
net-snmp-devel - update to 5.9-8
net-snmp-debuginfo - update to 5.9-8
net-snmp-debugsource - update to 5.9-8
net-snmp-perl - update to 5.9-8
net-snmp-libs - update to 5.9-8
net-snmp-gui - update to 5.9-8
python3-net-snmp - update to 5.9-8
net-snmp - update to 5.9-8
RecoverPoint for VMs - update to 6.0.SP1.P1
RSA Authentication Manager - update to 8.7 Patch 3
IBM Security Verify Governance - update to 10.0.2.0.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins