Vulnerability Name: | CVE-2005-2177 (CCN-21246) | ||||||||||||||||||||||||
Assigned: | 2005-07-01 | ||||||||||||||||||||||||
Published: | 2005-07-01 | ||||||||||||||||||||||||
Updated: | 2018-10-19 | ||||||||||||||||||||||||
Summary: | Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Mon Nov 21 2005 - 05:07:43 CST [USN-190-2] ucs-snmp vulnerability Source: CCN Type: Full-Disclosure Mailing List, Mon Nov 13 2006 - 17:22:20 CST VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1 Source: CCN Type: Full-Disclosure Mailing List, Mon Nov 13 2006 - 17:22:54 CST VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2 Source: CCN Type: Full-Disclosure Mailing List, Mon Nov 13 2006 - 17:22:38 CST VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4 Source: MITRE Type: CNA CVE-2005-2177 Source: CCN Type: SourceForge.net Current release: 5.2.1 Source: CCN Type: RHSA-2005-373 net-snmp security update Source: CCN Type: RHSA-2005-395 net-snmp security update Source: CCN Type: RHSA-2005-720 ucd-snmp security update Source: CCN Type: SA15930 Net-snmp Stream-based Protocol Denial of Service Source: SECUNIA Type: Vendor Advisory 15930 Source: SECUNIA Type: Vendor Advisory 16999 Source: SECUNIA Type: Vendor Advisory 17007 Source: SECUNIA Type: Vendor Advisory 17135 Source: CCN Type: SA17217 Avaya Modular Messaging ucd-snmp Denial of Service Vulnerability Source: SECUNIA Type: Vendor Advisory 17217 Source: SECUNIA Type: Vendor Advisory 17282 Source: SECUNIA Type: Vendor Advisory 17343 Source: SECUNIA Type: Vendor Advisory 18635 Source: CCN Type: SA22875 VMware ESX Server Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 22875 Source: CCN Type: SA23058 Solaris Net-SNMP Denial of Service Vulnerability Source: SECUNIA Type: Vendor Advisory 23058 Source: CCN Type: SA25373 Solaris 10 Net-snmp Stream-based Protocol Denial of Service Source: SECUNIA Type: Vendor Advisory 25373 Source: SECUNIA Type: Vendor Advisory 25432 Source: SECUNIA Type: Vendor Advisory 25787 Source: CCN Type: SECTRACK ID: 1017273 Net-SNMP Lets Remote Users Deny Service Source: SECTRACK Type: UNKNOWN 1017273 Source: MLIST Type: Patch [net-snmp-announce] 20050701 Multiple new Net-SNMP releases to fix a security related bug Source: SUNALERT Type: UNKNOWN 102725 Source: CONFIRM Type: UNKNOWN http://support.avaya.com/elmodocs2/security/ASA-2005-225.pdf Source: CCN Type: ASA-2006-283 A Malformed Packet Received by snmpd(1) via TCP may Cause a Denial of Service (DoS) Source: DEBIAN Type: UNKNOWN DSA-873 Source: DEBIAN Type: DSA-873 net-snmp -- programming error Source: MANDRIVA Type: UNKNOWN MDKSA-2006:025 Source: MISC Type: UNKNOWN http://www.net-snmp.org/about/ChangeLog.html Source: SUSE Type: UNKNOWN SUSE-SR:2005:024 Source: SUSE Type: UNKNOWN SUSE-SR:2007:012 Source: SUSE Type: UNKNOWN SUSE-SR:2007:013 Source: REDHAT Type: UNKNOWN RHSA-2005:373 Source: REDHAT Type: UNKNOWN RHSA-2005:395 Source: REDHAT Type: UNKNOWN RHSA-2005:720 Source: BUGTRAQ Type: UNKNOWN 20061113 VMSA-2006-0006 - VMware ESX Server 2.5.3 Upgrade Patch 4 Source: BUGTRAQ Type: UNKNOWN 20061113 VMSA-2006-0007 - VMware ESX Server 2.1.3 Upgrade Patch 2 Source: BUGTRAQ Type: UNKNOWN 20061113 VMSA-2006-0005 - VMware ESX Server 2.5.4 Upgrade Patch 1 Source: BUGTRAQ Type: UNKNOWN 20061113 VMSA-2006-0008 - VMware ESX Server 2.0.2 Upgrade Patch 2 Source: BID Type: UNKNOWN 14168 Source: CCN Type: BID-14168 Net-SNMP Unspecified Remote Stream-Based Protocol Denial Of Service Vulnerability Source: BID Type: UNKNOWN 21256 Source: CCN Type: BID-21256 Retired: Net-SNMP Unspecified Malformed TCP Packet Remote Denial Of Service Vulnerability Source: TRUSTIX Type: Patch, Vendor Advisory 2005-0034 Source: CCN Type: USN-190-1 SNMP vulnerability Source: UBUNTU Type: UNKNOWN USN-190-1 Source: CCN Type: USN-190-2 ucs-snmp vulnerability Source: CONFIRM Type: UNKNOWN http://www.vmware.com/download/esx/esx-202-200610-patch.html Source: CCN Type: VMware Web site VMware ESX Server 2.1.3 Upgrade Patch 2 (for 2.1.3 Systems Only) Source: CONFIRM Type: UNKNOWN http://www.vmware.com/download/esx/esx-213-200610-patch.html Source: CCN Type: VMware Advisory esx-253-200610-patch VMware ESX Server 2.5.3 Upgrade Patch 4 (for 2.5.3 Systems Only) Source: CONFIRM Type: UNKNOWN http://www.vmware.com/download/esx/esx-254-200610-patch.html Source: VUPEN Type: Vendor Advisory ADV-2006-4502 Source: VUPEN Type: Vendor Advisory ADV-2006-4677 Source: VUPEN Type: Vendor Advisory ADV-2007-1883 Source: XF Type: UNKNOWN netsnmp-streambased-dos(21246) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9986 Source: SUSE Type: SUSE-SR:2005:024 SUSE Security Summary Report Source: SUSE Type: SUSE-SR:2007:012 SUSE Security Summary Report Source: SUSE Type: SUSE-SR:2007:013 SUSE Security Summary Report | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |