Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian: DSA-1663-1 Moderate: Net-SNMP Buffer Overflow and Spoofing

debian
Calendar Grey November 9, 2008
Debian Logo
Debian has released updates for Net-SNMP to resolve security vulnerabilities, notably addressing issues such as buffer overflow exploits and spoofing attacks.
Several vulnerabilities have been discovered in NET SNMP, a suite of Simple Network Management Protocol applications

Summary


Wes Hardaker reported that the SNMPv3 HMAC verification relies on
the client to specify the HMAC length, which allows spoofing of
authenticated SNMPv3 packets.

CVE-2008-2292

John Kortink reported a buffer overflow in the __snprint_value
function in snmp_get causing a denial of service and potentially
allowing the execution of arbitrary code via a large OCTETSTRING
in an attribute value pair (AVP).

CVE-2008-4309

It was reported that an integer overflow in the
netsnmp_create_subtree_cache function in agent/snmp_agent.c allows
remote attackers to cause a denial of service attack via a crafted
SNMP GETBULK request.

For the stable distribution (etch), these problems has been fixed in
version 5.2.3-7etch4.

For the testing distribution (lenny) and unstable distribution (sid)
these problems have been fixed in version 5.4.1~dfsg-11.

We recommend that you upgrade your net-snmp package.

Upgrade instructions
- --------------------w...

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here