ALAS2-2020-1454

Related Vulnerabilities: CVE-2018-18066  

snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. (CVE-2018-18066)

ALAS2-2020-1454


Amazon Linux 2 Security Advisory: ALAS-2020-1454
Advisory Release Date: 2020-07-14 02:36 Pacific
Advisory Updated Date: 2020-07-17 00:46 Pacific
Severity: Medium
References: CVE-2018-18066 

Issue Overview:

snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. (CVE-2018-18066)


Affected Packages:

net-snmp


Issue Correction:
Run yum update net-snmp to update your system.

New Packages:
aarch64:
    net-snmp-5.7.2-48.amzn2.1.aarch64
    net-snmp-utils-5.7.2-48.amzn2.1.aarch64
    net-snmp-devel-5.7.2-48.amzn2.1.aarch64
    net-snmp-perl-5.7.2-48.amzn2.1.aarch64
    net-snmp-gui-5.7.2-48.amzn2.1.aarch64
    net-snmp-libs-5.7.2-48.amzn2.1.aarch64
    net-snmp-agent-libs-5.7.2-48.amzn2.1.aarch64
    net-snmp-python-5.7.2-48.amzn2.1.aarch64
    net-snmp-sysvinit-5.7.2-48.amzn2.1.aarch64
    net-snmp-debuginfo-5.7.2-48.amzn2.1.aarch64

i686:
    net-snmp-5.7.2-48.amzn2.1.i686
    net-snmp-utils-5.7.2-48.amzn2.1.i686
    net-snmp-devel-5.7.2-48.amzn2.1.i686
    net-snmp-perl-5.7.2-48.amzn2.1.i686
    net-snmp-gui-5.7.2-48.amzn2.1.i686
    net-snmp-libs-5.7.2-48.amzn2.1.i686
    net-snmp-agent-libs-5.7.2-48.amzn2.1.i686
    net-snmp-python-5.7.2-48.amzn2.1.i686
    net-snmp-sysvinit-5.7.2-48.amzn2.1.i686
    net-snmp-debuginfo-5.7.2-48.amzn2.1.i686

src:
    net-snmp-5.7.2-48.amzn2.1.src

x86_64:
    net-snmp-5.7.2-48.amzn2.1.x86_64
    net-snmp-utils-5.7.2-48.amzn2.1.x86_64
    net-snmp-devel-5.7.2-48.amzn2.1.x86_64
    net-snmp-perl-5.7.2-48.amzn2.1.x86_64
    net-snmp-gui-5.7.2-48.amzn2.1.x86_64
    net-snmp-libs-5.7.2-48.amzn2.1.x86_64
    net-snmp-agent-libs-5.7.2-48.amzn2.1.x86_64
    net-snmp-python-5.7.2-48.amzn2.1.x86_64
    net-snmp-sysvinit-5.7.2-48.amzn2.1.x86_64
    net-snmp-debuginfo-5.7.2-48.amzn2.1.x86_64