snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB file, as demonstrated by a NULL type in an ifMtu trap message.
{ "ubuntu_priority": "low", "availability": "No subscription required", "binaries": [ { "binary_name": "libsnmp-base", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "libsnmp-dev", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "libsnmp-dev-dbgsym", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "libsnmp-perl", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "libsnmp-perl-dbgsym", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "libsnmp30", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "libsnmp30-dbg", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "libsnmp30-dbgsym", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "python-netsnmp", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "python-netsnmp-dbgsym", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "snmp", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "snmp-dbgsym", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "snmpd", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "snmpd-dbgsym", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" }, { "binary_name": "tkmib", "binary_version": "5.7.2~dfsg-8.1ubuntu3.1" } ] }