Gentoo Archives: gentoo-dev

From: Ferry Meyndert <m0rpheus@g.o>
To: gentoo-anounce@g.o, gentoo-user@g.o, gentoo-dev@g.o
Subject: [gentoo-dev] [GENTOO LINUX SECURITY ANNOUNCEMENT] New ucd-snmp version too fix multiple vulnerabilities in SNMPv1 request handling
Date: Tue, 12 Feb 2002 19:04:30
Message-Id: 20020213020122.2b7c0212.m0rpheus@gentoo.org
1 - --------------------------------------------------------------------------
2 GENTOO LINUX SECURITY ANNOUNCEMENT
3 - --------------------------------------------------------------------------
4
5 PACKAGE :ucd-snmp
6 SUMMARY :Multiple vulnerabilities in SNMPv1 request handling
7 DATE :2002-02-14 01:32:00
8
9 - --------------------------------------------------------------------------
10
11 OVERVIEW
12
13 The Simple Network Management Protocol (SNMP) enables
14 monitoring and configuration of network nodes.
15
16 The Oulu University Secure Programming Group performed
17 a vulnerability assessment of various SNMP implementations through syntax
18 testing and test-suite creation.
19
20 The test-suite showed several failures in the ucd-snmp tools in version
21 4.2.2 and earlier. These vulnerabilities can cause denial-of-service
22 conditions, service interruptions, and in some cases could result in a
23 remote security breach.
24
25 The Common Vulnerabilities and Exposures project (cve.mitre.org) has
26 assigned the names CAN-2002-0012 and CAN-2002-0013 to these issues.
27
28
29 DETAIL
30
31 http://www.kb.cert.org/vuls/id/854306
32
33
34
35 SOLUTION
36
37
38 It is recommended that all ucd-snmp users apply the update
39
40 Portage Auto:
41
42 emerge rsync
43 emerge update
44 emerge update --world
45
46
47 Portage by hand:
48
49 emerge rsync
50 emerge net-analyzer/ucd-snmp
51
52 Manually:
53
54 Download the new ucd-snmp package here and follow in file instructions:
55 http://prdownloads.sourceforge.net/net-snmp/ucd-snmp-4.2.3.tar.gz
56
57
58 NEWS
59
60 From now on gentoo security anouncements will be made at the gentoo-anounce
61 mailinglist. So if your not subscribed allready make sure you subscribe yourself too keep updated.
62
63 You can subscribe yourself too the gentoo-anounce mailinglist here:
64 http://lists.gentoo.org/mailman/listinfo/gentoo-announce
65
66 - --------------------------------------------------------------------------
67 Ferry Meyndert
68 m0rpheus@g.o
69 - --------------------------------------------------------------------------