1 |
- -------------------------------------------------------------------------- |
2 |
GENTOO LINUX SECURITY ANNOUNCEMENT |
3 |
- -------------------------------------------------------------------------- |
4 |
|
5 |
PACKAGE :ucd-snmp |
6 |
SUMMARY :Multiple vulnerabilities in SNMPv1 request handling |
7 |
DATE :2002-02-14 01:32:00 |
8 |
|
9 |
- -------------------------------------------------------------------------- |
10 |
|
11 |
OVERVIEW |
12 |
|
13 |
The Simple Network Management Protocol (SNMP) enables |
14 |
monitoring and configuration of network nodes. |
15 |
|
16 |
The Oulu University Secure Programming Group performed |
17 |
a vulnerability assessment of various SNMP implementations through syntax |
18 |
testing and test-suite creation. |
19 |
|
20 |
The test-suite showed several failures in the ucd-snmp tools in version |
21 |
4.2.2 and earlier. These vulnerabilities can cause denial-of-service |
22 |
conditions, service interruptions, and in some cases could result in a |
23 |
remote security breach. |
24 |
|
25 |
The Common Vulnerabilities and Exposures project (cve.mitre.org) has |
26 |
assigned the names CAN-2002-0012 and CAN-2002-0013 to these issues. |
27 |
|
28 |
|
29 |
DETAIL |
30 |
|
31 |
http://www.kb.cert.org/vuls/id/854306 |
32 |
|
33 |
|
34 |
|
35 |
SOLUTION |
36 |
|
37 |
|
38 |
It is recommended that all ucd-snmp users apply the update |
39 |
|
40 |
Portage Auto: |
41 |
|
42 |
emerge rsync |
43 |
emerge update |
44 |
emerge update --world |
45 |
|
46 |
|
47 |
Portage by hand: |
48 |
|
49 |
emerge rsync |
50 |
emerge net-analyzer/ucd-snmp |
51 |
|
52 |
Manually: |
53 |
|
54 |
Download the new ucd-snmp package here and follow in file instructions: |
55 |
http://prdownloads.sourceforge.net/net-snmp/ucd-snmp-4.2.3.tar.gz |
56 |
|
57 |
|
58 |
NEWS |
59 |
|
60 |
From now on gentoo security anouncements will be made at the gentoo-anounce |
61 |
mailinglist. So if your not subscribed allready make sure you subscribe yourself too keep updated. |
62 |
|
63 |
You can subscribe yourself too the gentoo-anounce mailinglist here: |
64 |
http://lists.gentoo.org/mailman/listinfo/gentoo-announce |
65 |
|
66 |
- -------------------------------------------------------------------------- |
67 |
Ferry Meyndert |
68 |
m0rpheus@g.o |
69 |
- -------------------------------------------------------------------------- |