CVE-2010-2891
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 14%
from disclosure to weapon0 days
Published on NVDOct 27
1st PoCOct 20
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by . (dot) characters.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/15293unverifiedexploitdbwww.exploit-db.com/exploits/15293unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/41841http://secunia.com/advisories/42877http://secunia.com/advisories/42902http://secunia.com/advisories/43068http://security-tracker.debian.org/tracker/CVE-2010-2891https://exchange.xforce.ibmcloud.com/vulnerabilities/62686http://www.coresecurity.com/content/libsmi-smigetnode-buffer-overflowhttp://www.debian.org/security/2011/dsa-2145http://www.exploit-db.com/exploits/15293http://www.mandriva.com/security/advisories?name=MDVSA-2010:209