← Vulnerability feed

Vulnerability record · CVE-2008-2292 · published 18 May 2008

CVE-2008-2292: Net-snmp memory buffer overflow vulnerability

Net Snmp · Net Snmp

Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large OCTETSTRING in an attribute value pair (AVP).

6.8 CVSS 2.0 Medium EPSS 8.4% · top 5.2% CWE-119 · Memory buffer overflow
6.8CVSS 2.0 base score
8.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
60References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large OCTETSTRING in an attribute value pair (AVP).

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00000.html
http://secunia.com/advisories/30187 Vendor Advisory
http://secunia.com/advisories/30615
http://secunia.com/advisories/30647
http://secunia.com/advisories/31155
http://secunia.com/advisories/31334
http://secunia.com/advisories/31351
http://secunia.com/advisories/31467
http://secunia.com/advisories/31568
http://secunia.com/advisories/32664
http://secunia.com/advisories/33003
http://security.gentoo.org/glsa/glsa-200808-02.xml
http://sourceforge.net/tracker/index.php?func=detail&aid=1826174&group_id=12694&atid=112694
http://sunsolve.sun.com/search/document.do?assetkey=1-26-239785-1
http://support.avaya.com/elmodocs2/security/ASA-2008-282.htm
http://www.debian.org/security/2008/dsa-1663
http://www.mandriva.com/security/advisories?name=MDVSA-2008:118
http://www.redhat.com/support/errata/RHSA-2008-0529.html
http://www.securityfocus.com/bid/29212
http://www.securitytracker.com/id?1020527
http://www.ubuntu.com/usn/usn-685-1
http://www.vmware.com/security/advisories/VMSA-2008-0013.html
http://www.vupen.com/english/advisories/2008/1528/references
http://www.vupen.com/english/advisories/2008/2141/references
http://www.vupen.com/english/advisories/2008/2361
https://exchange.xforce.ibmcloud.com/vulnerabilities/42430
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11261
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00363.html
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00380.html
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00459.html
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00000.html
http://secunia.com/advisories/30187 Vendor Advisory
http://secunia.com/advisories/30615
http://secunia.com/advisories/30647
http://secunia.com/advisories/31155
http://secunia.com/advisories/31334
http://secunia.com/advisories/31351
http://secunia.com/advisories/31467
http://secunia.com/advisories/31568
http://secunia.com/advisories/32664

Track CVE-2008-2292 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-4837Net-snmp vulnerabilitysnmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote …EPSS 9.7%10.0CVE-2005-1740Net-snmp vulnerabilityfixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute…EPSS 8.6%9.8CVE-2025-68615Net-snmp memory buffer overflow vulnerabilitynet-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd …EPSS 42%9.8CVE-2018-1000116Net-snmp out-of-bounds write vulnerabilityNET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.EPSS 6.3%8.8CVE-2022-24810Net-snmp null pointer dereference vulnerabilitynet-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can us…EPSS 1.1%8.8CVE-2022-24805Net-snmp classic buffer overflow vulnerabilitynet-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the …EPSS 1.3%7.8CVE-2020-15861Net-snmp link following vulnerabilityNet-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.EPSS 0.46%7.8CVE-2020-15862Net-snmp improper privilege management vulnerabilityNet-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as …EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2008-2292), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.