Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1516447 - (CVE-2017-16820) CVE-2017-16820 collectd: double free in csnmp_read_table function in snmp.c
CVE-2017-16820 collectd: double free in csnmp_read_table function in snmp.c
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20171114,repor...
: Security
Depends On: 1558834 1558835 1516449 1516450 1516451 1517567 1517568 1540409 1541204 1550290 1558823
Blocks: 1516452
  Show dependency treegraph
 
Reported: 2017-11-22 11:07 EST by Pedro Sampaio
Modified: 2018-09-04 02:39 EDT (History)
37 users (show)

See Also:
Fixed In Version: collectd 5.8.0, collectd 5.6.3
Doc Type: If docs needed, set a value
Doc Text:
A double-free vulnerability was found in the csnmp_read_table function in the SNMP plugin of collectd. A network-based attacker could exploit this by sending malformed data, causing collectd to crash or possibly other impact.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:0252 normal SHIPPED_LIVE Moderate: collectd security update 2018-01-30 21:08:56 EST
Red Hat Product Errata RHSA-2018:0299 normal SHIPPED_LIVE Moderate: collectd security update 2018-02-13 16:13:11 EST
Red Hat Product Errata RHSA-2018:0560 None None None 2018-03-20 12:36 EDT
Red Hat Product Errata RHSA-2018:1605 None None None 2018-05-17 11:26 EDT
Red Hat Product Errata RHSA-2018:2615 None None None 2018-09-04 02:39 EDT

  None (edit)
Description Pedro Sampaio 2017-11-22 11:07:48 EST
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).

Upstream bug:

https://github.com/collectd/collectd/issues/2291

Upstream patch:

https://github.com/collectd/collectd/commit/d16c24542b2f96a194d43a73c2e5778822b9cb47

References:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881757
Comment 1 Pedro Sampaio 2017-11-22 11:08:51 EST
Created collectd tracking bugs for this issue:

Affects: epel-6 [bug 1516449]
Affects: epel-7 [bug 1516450]
Affects: fedora-all [bug 1516451]
Comment 2 Joshua Padman 2017-11-23 00:59:38 EST
Versions 5.7.x are vulnerable too.

Conditions exist in OSP11/12 package collectd-5.7.2-1.1.el7ost. Still completing analysis.
Comment 3 Joshua Padman 2017-11-24 00:59:18 EST
Still determining severity for OSP. collectd was tech preview in 7-9 so marking won't fix for those.
Comment 4 Joshua Padman 2017-11-26 17:10:26 EST
collectd is in tech preview in OSP10 as well, marked accordingly.

Fixing in OSP11-12 partly because the security risk but also as a reasonable use case also has potential to crash the application.
Comment 6 errata-xmlrpc 2018-01-30 16:08:27 EST
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 12.0 Operational Tools for RHEL 7

Via RHSA-2018:0252 https://access.redhat.com/errata/RHSA-2018:0252
Comment 10 errata-xmlrpc 2018-02-13 11:12:39 EST
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 11.0 Operational Tools for RHEL 7

Via RHSA-2018:0299 https://access.redhat.com/errata/RHSA-2018:0299
Comment 13 errata-xmlrpc 2018-03-20 12:35:43 EDT
This issue has been addressed in the following products:

  Red Hat Virtualization 4 for RHEL-7
  Red Hat Virtualization Engine 4.1

Via RHSA-2018:0560 https://access.redhat.com/errata/RHSA-2018:0560
Comment 16 errata-xmlrpc 2018-05-17 11:26:16 EDT
This issue has been addressed in the following products:

  Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7

Via RHSA-2018:1605 https://access.redhat.com/errata/RHSA-2018:1605
Comment 18 errata-xmlrpc 2018-09-04 02:39:04 EDT
This issue has been addressed in the following products:

  Red Hat Gluster Storage 3.4 for RHEL 7

Via RHSA-2018:2615 https://access.redhat.com/errata/RHSA-2018:2615

Note You need to log in before you can comment on or make changes to this bug.