Description
Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.
Published: 2008-10-31
Score: 5.0 Medium
EPSS: 11.1% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1663-1 New net-snmp packages fix several vulnerabilities
Ubuntu USN Ubuntu USN USN-685-1 Net-SNMP vulnerabilities
References
Link Providers
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2010//Dec/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=125017764422557&w=2 cve-icon cve-icon
http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/tags/Ext-5-2-5-1/net-snmp/agent/snmp_agent.c?r1=17271&r2=17272&pathrev=17272 cve-icon cve-icon
http://secunia.com/advisories/32539 cve-icon cve-icon
http://secunia.com/advisories/32560 cve-icon cve-icon
http://secunia.com/advisories/32664 cve-icon cve-icon
http://secunia.com/advisories/32711 cve-icon cve-icon
http://secunia.com/advisories/33003 cve-icon cve-icon
http://secunia.com/advisories/33095 cve-icon cve-icon
http://secunia.com/advisories/33631 cve-icon cve-icon
http://secunia.com/advisories/33746 cve-icon cve-icon
http://secunia.com/advisories/33821 cve-icon cve-icon
http://secunia.com/advisories/35074 cve-icon cve-icon
http://secunia.com/advisories/35679 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200901-15.xml cve-icon cve-icon
http://sourceforge.net/forum/forum.php?forum_id=882903 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-262908-1 cve-icon cve-icon
http://support.apple.com/kb/HT3549 cve-icon cve-icon
http://support.apple.com/kb/HT4298 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2008-467.htm cve-icon cve-icon
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0315 cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1663 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:225 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2008/10/31/1 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0971.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/498280/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/32020 cve-icon cve-icon
http://www.securitytracker.com/id?1021129 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-685-1 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA09-133A.html cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2009-0001.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2973 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/3400 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/0301 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/1297 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/1771 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/46262 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2008-4309 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6171 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6353 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9860 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2008-4309 cve-icon
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.08604}

epss

{'score': 0.11144}


Subscriptions

Net-snmp Net-snmp
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T10:08:35.116Z

Reserved: 2008-09-29T00:00:00.000Z

Link: CVE-2008-4309

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2008-10-31T20:29:09.497

Modified: 2026-04-23T00:35:47.467

Link: CVE-2008-4309

cve-icon Redhat

Severity : Important

Publid Date: 2008-10-31T00:00:00Z

Links: CVE-2008-4309 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses