Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Debian: DSA-111-1 Critical Advisory for Ucd-snmp Remote Exploit

debian
Calendar Grey February 14, 2002
Debian Logo
Address security threats by upgrading ucd-snmp modules in accordance with the official advisory DSA-111-1 released by Debian.
These packages prevent possible denial of service ...

Summary

Package : ucd-snmp
Problem type : remote exploit
Debian-specific: no
CERT Advisory : CA-2002-03

The Secure Programming Group of the Oulu University did a study on
SNMP implementations and uncovered multiple problems which can
cause problems ranging from Denial of Service attacks to remote
exploits.

New UCD-SNMP packages have been prepared to fix these problems
as well as a few others. The complete list of fixed problems is:

* When running external programs snmpd used temporary files insecurely
* snmpd did not properly reset supplementary groups after changing
its uid and gid
* Modified most code to use buffers instead of fixed-length strings to
prevent buffer overflows
* The ASN.1 parser did not check for negative lengths
* the IFINDEX response handling in snmpnetstat did not do a sanity check
on its input

(thanks to Caldera for most of the work on those patches)

The new version is 4.1.1-2.1 and we recommend you upgrade your
snmp packages immediately.

wget url
will fetch the file ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here