The vendor explicitly identifies these products as affected by this CVE.
- net-snmp as a component of Red Hat Enterprise Linux 6
- net-snmp-devel as a component of Red Hat Enterprise Linux 6
- net-snmp-libs as a component of Red Hat Enterprise Linux 6
- net-snmp-perl as a component of Red Hat Enterprise Linux 6
- net-snmp-python as a component of Red Hat Enterprise Linux 6
- net-snmp-utils as a component of Red Hat Enterprise Linux 6
- net-snmp.src as a component of Red Hat Enterprise Linux 6
- openshift/ose-rhel-coreos-9 as a component of Red Hat OpenShift Container Platform 4
- Summary
- A flaw was found in net-snmp. A remote attacker can trigger a buffer overflow in the snmptrapd daemon by sending a specially crafted SNMP packet, causing the daemon to crash and resulting in a denial of service.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
