LIN6-9937 : CLONE - CLONE - net-snmp: snmp_pdu_parse() incompletely parsed varBinds left in list of variables

Created: May 28, 2015    Updated: Dec 3, 2018
Resolved Date: Jun 17, 2015
Previous ID: LIN5-20457
Found In Version:
Fix Version:
Severity: Standard
Applicable for: Wind River Linux 6
Component/s: Userspace


It was discovered that the snmp_pdu_parse() function could leave incompletely parsed varBind variables in the list of variables. A remote, unauthenticated attacker could exploit this flaw to cause a crash or, potentially, execute arbitrary code.

