SCIENTIFIC-LINUX-ERRATA Archives

March 2014

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Condense Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Content-Transfer-Encoding:
7bit
Sender:
Security Errata for Scientific Linux <[log in to unmask]>
Subject:
From:
Pat Riehecky <[log in to unmask]>
Date:
Mon, 24 Mar 2014 19:13:48 +0000
MIME-Version:
1.0
Content-Type:
text/plain; charset="utf-8"
Reply-To:
Parts/Attachments:
text/plain (44 lines)
Synopsis:          Moderate: net-snmp security update
Advisory ID:       SLSA-2014:0322-1
Issue Date:        2014-03-24
CVE Numbers:       CVE-2012-6151
                   CVE-2014-2285
--

A denial of service flaw was found in the way snmpd, the Net-SNMP daemon,
handled subagent timeouts. A remote attacker able to trigger a subagent
timeout could use this flaw to cause snmpd to loop infinitely or crash.
(CVE-2012-6151)

A denial of service flaw was found in the way the snmptrapd service, which
receives and logs SNMP trap messages, handled SNMP trap requests with an
empty community string when the Perl handler (provided by the net-snmp-
perl package) was enabled. A remote attacker could use this flaw to crash
snmptrapd by sending a trap request with an empty community string.
(CVE-2014-2285)

After installing this update, the snmpd and snmptrapd services will be
restarted automatically.
--

SL5
  x86_64
    net-snmp-5.3.2.2-22.el5_10.1.x86_64.rpm
    net-snmp-debuginfo-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-debuginfo-5.3.2.2-22.el5_10.1.x86_64.rpm
    net-snmp-libs-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-libs-5.3.2.2-22.el5_10.1.x86_64.rpm
    net-snmp-perl-5.3.2.2-22.el5_10.1.x86_64.rpm
    net-snmp-utils-5.3.2.2-22.el5_10.1.x86_64.rpm
    net-snmp-devel-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-devel-5.3.2.2-22.el5_10.1.x86_64.rpm
  i386
    net-snmp-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-debuginfo-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-libs-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-perl-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-utils-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-devel-5.3.2.2-22.el5_10.1.i386.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2