First published: Mon Nov 03 2008(Updated: )
The Simple Network Management Protocol (SNMP) is a protocol used for<br>network management.<br>A denial-of-service flaw was found in the way Net-SNMP processes SNMP<br>GETBULK requests. A remote attacker who issued a specially-crafted request<br>could cause the snmpd server to crash. (CVE-2008-4309)<br>Note: An attacker must have read access to the SNMP server in order to<br>exploit this flaw. In the default configuration, the community name<br>"public" grants read-only access. In production deployments, it is<br>recommended to change this default community name.<br>All users of net-snmp should upgrade to these updated packages, which<br>contain a backported patch to resolve this issue.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/net-snmp | <5.3.1-24.el5_2.2 | 5.3.1-24.el5_2.2 |
redhat/net-snmp | <5.3.1-24.el5_2.2 | 5.3.1-24.el5_2.2 |
redhat/net-snmp-devel | <5.3.1-24.el5_2.2 | 5.3.1-24.el5_2.2 |
redhat/net-snmp-devel | <5.3.1-24.el5_2.2 | 5.3.1-24.el5_2.2 |
redhat/net-snmp-libs | <5.3.1-24.el5_2.2 | 5.3.1-24.el5_2.2 |
redhat/net-snmp-libs | <5.3.1-24.el5_2.2 | 5.3.1-24.el5_2.2 |
redhat/net-snmp-perl | <5.3.1-24.el5_2.2 | 5.3.1-24.el5_2.2 |
redhat/net-snmp-utils | <5.3.1-24.el5_2.2 | 5.3.1-24.el5_2.2 |
redhat/net-snmp-perl | <5.3.1-24.el5_2.2 | 5.3.1-24.el5_2.2 |
redhat/net-snmp-utils | <5.3.1-24.el5_2.2 | 5.3.1-24.el5_2.2 |
redhat/net-snmp | <5.1.2-13.el4_7.2 | 5.1.2-13.el4_7.2 |
redhat/net-snmp | <5.1.2-13.el4_7.2 | 5.1.2-13.el4_7.2 |
redhat/net-snmp-devel | <5.1.2-13.el4_7.2 | 5.1.2-13.el4_7.2 |
redhat/net-snmp-libs | <5.1.2-13.el4_7.2 | 5.1.2-13.el4_7.2 |
redhat/net-snmp-libs | <5.1.2-13.el4_7.2 | 5.1.2-13.el4_7.2 |
redhat/net-snmp-perl | <5.1.2-13.el4_7.2 | 5.1.2-13.el4_7.2 |
redhat/net-snmp-utils | <5.1.2-13.el4_7.2 | 5.1.2-13.el4_7.2 |
redhat/net-snmp-devel | <5.1.2-13.el4_7.2 | 5.1.2-13.el4_7.2 |
redhat/net-snmp-perl | <5.1.2-13.el4_7.2 | 5.1.2-13.el4_7.2 |
redhat/net-snmp-utils | <5.1.2-13.el4_7.2 | 5.1.2-13.el4_7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.