CVE-2006-2444
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 21%
from disclosure to weapon11 days
Published on NVDMay 25
1st PoC+11d
exploitation probability
21%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random memory or (2) frees of previously-freed memory (double-free) by snmp_trap_decode as well as its calling function, as demonstrated via certain test cases of the PROTOS SNMP test suite.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/1880⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.18http://secunia.com/advisories/20182http://secunia.com/advisories/20225http://secunia.com/advisories/20716http://secunia.com/advisories/21035http://secunia.com/advisories/21136http://secunia.com/advisories/21179http://secunia.com/advisories/21498http://secunia.com/advisories/21605http://secunia.com/advisories/21983http://secunia.com/advisories/22082http://secunia.com/advisories/22093