SCIENTIFIC-LINUX-ERRATA Archives

March 2014

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 24 Mar 2014 19:13:48 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (44 lines)
Synopsis:          Moderate: net-snmp security update
Advisory ID:       SLSA-2014:0322-1
Issue Date:        2014-03-24
CVE Numbers:       CVE-2012-6151
                   CVE-2014-2285
--

A denial of service flaw was found in the way snmpd, the Net-SNMP daemon,
handled subagent timeouts. A remote attacker able to trigger a subagent
timeout could use this flaw to cause snmpd to loop infinitely or crash.
(CVE-2012-6151)

A denial of service flaw was found in the way the snmptrapd service, which
receives and logs SNMP trap messages, handled SNMP trap requests with an
empty community string when the Perl handler (provided by the net-snmp-
perl package) was enabled. A remote attacker could use this flaw to crash
snmptrapd by sending a trap request with an empty community string.
(CVE-2014-2285)

After installing this update, the snmpd and snmptrapd services will be
restarted automatically.
--

SL5
  x86_64
    net-snmp-5.3.2.2-22.el5_10.1.x86_64.rpm
    net-snmp-debuginfo-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-debuginfo-5.3.2.2-22.el5_10.1.x86_64.rpm
    net-snmp-libs-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-libs-5.3.2.2-22.el5_10.1.x86_64.rpm
    net-snmp-perl-5.3.2.2-22.el5_10.1.x86_64.rpm
    net-snmp-utils-5.3.2.2-22.el5_10.1.x86_64.rpm
    net-snmp-devel-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-devel-5.3.2.2-22.el5_10.1.x86_64.rpm
  i386
    net-snmp-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-debuginfo-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-libs-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-perl-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-utils-5.3.2.2-22.el5_10.1.i386.rpm
    net-snmp-devel-5.3.2.2-22.el5_10.1.i386.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2