CVE-2020-24361

Name
CVE-2020-24361
Description
SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Release Notes http://www.snmptt.org/changelog.shtml
Third Party Advisory https://security.gentoo.org/glsa/202007-63
MLIST https://lists.debian.org/debian-lts-announce/2020/10/msg00006.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:snmptt:snmptt:*:*:*:*:*:*:*:* snmptt >= None < 1.4.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
snmptt 3.13-main 1.4.2-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
snmptt 3.11-main 1.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
snmptt 3.10-main 1.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
snmptt 3.14-main 1.4.2-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
snmptt 3.12-main 1.4.2-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
snmptt 3.15-main 1.4.2-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
snmptt 3.16-main 1.4.2-r0 Natanael Copa <ncopa@alpinelinux.org> fixed