net-snmp vulnerability

Related Vulnerabilities: CVE-2008-6123  

UDP clients might be able to bypass access restrictions of the SNMP server.

The SNMP server did not correctly validate certain UDP clients when using TCP wrappers. Under some situations, a remote attacker could bypass access restrictions and communicate with the SNMP server, potentially leading to a loss of privacy or a denial of service.

2 June 2010

net-snmp vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 10.04 LTS

Summary

UDP clients might be able to bypass access restrictions of the SNMP server.

Software Description

  • net-snmp - Simple Network Management Protocol server and libraries

Details

The SNMP server did not correctly validate certain UDP clients when using TCP wrappers. Under some situations, a remote attacker could bypass access restrictions and communicate with the SNMP server, potentially leading to a loss of privacy or a denial of service.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 10.04 LTS
libsnmp15 - 5.4.2.1~dfsg0ubuntu1-0ubuntu2.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References