imPC@ndo IT

Tracker / CVE-2018-18065

CVE-2018-18065

Medium 6.5

_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

Affected products and versions

canonical ubuntu_linux
debian debian_linux
net-snmp net-snmp · … → 5.8
netapp cloud_backup
netapp data_ontap
netapp e-series_santricity_os_controller · 11.0 → 11.5
netapp hyper_converged_infrastructure
netapp solidfire_element_os
netapp storagegrid_webscale
paloaltonetworks pan-os · … → 7.1.22
paloaltonetworks pan-os · 7.1.23 → 8.0.15
paloaltonetworks pan-os · 8.0.16 → 8.1.6

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References