LWN.net Logo

net-snmp: restriction bypass

Package(s):net-snmp CVE #(s):CVE-2008-6123
Created:February 17, 2009 Updated:June 3, 2010
Description: From the CVE entry: The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion."
Alerts:
Ubuntu USN-946-1 2010-06-02
Gentoo 201001-05 2010-01-13
SuSE SUSE-SR:2010:003 2010-02-09
SuSE SUSE-SR:2009:012 2009-07-03
SuSE SUSE-SR:2009:011 2009-06-09
CentOS CESA-2009:0295 2009-03-26
Red Hat RHSA-2009:0295-01 2009-03-26
Mandriva MDVSA-2009:056 2009-02-25
Fedora FEDORA-2009-1769 2009-02-17

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds