Date: Mon, 3 Nov 2008 14:52:55 -0600 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for net-snmp on SL3.x, SL4.x, SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Important: net-snmp security update Issue date: 2008-11-03 CVE Names: CVE-2008-4309 A denial-of-service flaw was found in the way Net-SNMP processes SNMP GETBULK requests. A remote attacker who issued a specially-crafted request could cause the snmpd server to crash. (CVE-2008-4309) Note: An attacker must have read access to the SNMP server in order to exploit this flaw. In the default configuration, the community name "public" grants read-only access. In production deployments, it is recommended to change this default community name. SL 3.0.x SRPMS: net-snmp-5.0.9-2.30E.25.src.rpm i386: net-snmp-5.0.9-2.30E.25.i386.rpm net-snmp-devel-5.0.9-2.30E.25.i386.rpm net-snmp-libs-5.0.9-2.30E.25.i386.rpm net-snmp-perl-5.0.9-2.30E.25.i386.rpm net-snmp-utils-5.0.9-2.30E.25.i386.rpm x86_64: net-snmp-5.0.9-2.30E.25.x86_64.rpm net-snmp-devel-5.0.9-2.30E.25.x86_64.rpm net-snmp-libs-5.0.9-2.30E.25.i386.rpm net-snmp-libs-5.0.9-2.30E.25.x86_64.rpm net-snmp-perl-5.0.9-2.30E.25.x86_64.rpm net-snmp-utils-5.0.9-2.30E.25.x86_64.rpm SL 4.x SRPMS: net-snmp-5.1.2-13.el4_7.2.src.rpm i386: net-snmp-5.1.2-13.el4_7.2.i386.rpm net-snmp-devel-5.1.2-13.el4_7.2.i386.rpm net-snmp-libs-5.1.2-13.el4_7.2.i386.rpm net-snmp-perl-5.1.2-13.el4_7.2.i386.rpm net-snmp-utils-5.1.2-13.el4_7.2.i386.rpm x86_64: net-snmp-5.1.2-13.el4_7.2.x86_64.rpm net-snmp-devel-5.1.2-13.el4_7.2.x86_64.rpm net-snmp-libs-5.1.2-13.el4_7.2.i386.rpm net-snmp-libs-5.1.2-13.el4_7.2.x86_64.rpm net-snmp-perl-5.1.2-13.el4_7.2.x86_64.rpm net-snmp-utils-5.1.2-13.el4_7.2.x86_64.rpm SL 5.x SRPMS: net-snmp-5.3.1-24.el5_2.2.src.rpm i386: net-snmp-5.3.1-24.el5_2.2.i386.rpm net-snmp-devel-5.3.1-24.el5_2.2.i386.rpm net-snmp-libs-5.3.1-24.el5_2.2.i386.rpm net-snmp-perl-5.3.1-24.el5_2.2.i386.rpm net-snmp-utils-5.3.1-24.el5_2.2.i386.rpm x86_64: net-snmp-5.3.1-24.el5_2.2.x86_64.rpm net-snmp-devel-5.3.1-24.el5_2.2.i386.rpm net-snmp-devel-5.3.1-24.el5_2.2.x86_64.rpm net-snmp-libs-5.3.1-24.el5_2.2.i386.rpm net-snmp-libs-5.3.1-24.el5_2.2.x86_64.rpm net-snmp-perl-5.3.1-24.el5_2.2.x86_64.rpm net-snmp-utils-5.3.1-24.el5_2.2.x86_64.rpm -Connie Sieh -Troy Dawson