ALPINE-CVE-2022-44792 PUBLISHED CVSS 6.5 MEDIUM

handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.21net-snmp5.9.1-r7, 5.9.3-r0, 5.9.3-r1
Alpine:v3.20net-snmp5.9.1-r7, 5.9.3-r0, 5.9.3-r1
Alpine:v3.22net-snmp5.9.1-r4, 0, 5.4.2.1-r0
Alpine:v3.18net-snmp5.7.2-r0, 5.7.3-r9, 5.8-r0
Alpine:v3.14net-snmp5.7.3-r1, 5.7.3-r4, 5.7.3-r5
Alpine:v3.23net-snmp5.8-r1, 5.8-r2, 5.8-r3
Alpine:v3.16net-snmp5.9.1-r0, 0, 5.4.2.1-r0
Alpine:v3.15net-snmp0, 5.4.2.1-r0, 5.4.2.1-r1
Alpine:v3.19net-snmp5.7.3-r11, 5.7.3-r10, 5.7.3-r1
Alpine:v3.17net-snmp5.7.3-r11, 5.7.3-r10, 5.7.3-r1

Timeline

References

Open in Interactive Console →