First published: Thu Aug 09 2012(Updated: )
It was reported [1],[2]that the AgentX subagent of net-snmp could be stalled when a manager sent a multi-object request with a different number subids. This could lead to a denial of service. This has been corrected upstream in version 5.4.4 [3]; only earlier versiona are affected. This means that Fedora and Red Hat Enterprise Linux 6 are not affected, however Red Hat Enterprise Linux 5 does ship a vulnerable version (5.3.x). [1] <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684388">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684388</a> [2] <a href="http://seclists.org/oss-sec/2014/q1/513">http://seclists.org/oss-sec/2014/q1/513</a> [3] <a href="http://sourceforge.net/p/net-snmp/patches/1113/">http://sourceforge.net/p/net-snmp/patches/1113/</a> Statement: This issue did not affect the version of the net-snmp packages as shipped with Red Hat Enterprise Linux 6.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Net-snmp Net-snmp | <=5.4 | |
redhat/net-snmp | <5.4.4 | 5.4.4 |
debian/net-snmp | 5.9+dfsg-4+deb11u1 5.9.3+dfsg-2 5.9.4+dfsg-1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.