oss-sec mailing list archives

Re: SNMPD DoS #2411 snmpd crashes/hangs when AgentX subagent times-out


From: Kurt Seifried <kseifried () redhat com>
Date: Wed, 04 Dec 2013 13:00:33 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 12/02/2013 10:54 PM, Kurt Seifried wrote:
Just cleaning out old email, ran across this:

http://sourceforge.net/p/net-snmp/bugs/2411/

It's a DoS, requires authenticated access but snmpd is often used to
monitor a lot of systems not always under your direct control (e.g.
read only access). I'm inclined to assign a CVE unless someone objects
strongly.

Please use CVE-2012-6151 for this issue.

- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.15 (GNU/Linux)

iQIcBAEBAgAGBQJSn4nhAAoJEBYNRVNeJnmTkXIP/2aUuLaKF1kfF8e9ZbN/8KBj
m9ry80sAPt58JQLNtTuKImW5HQ12N1A5lYeDoqgHpS9/RUka6GSUApgRr7Z7qv4m
5loGnswD0Y4SB7kdM2YSUuRqPo3CGUnlbE1GWZMUxQlQKdItrbQmatxhRAUzpYVR
TkW8zMUJ0CvT5th3OlTqRW82FzQB9e69qXWEtfCxuk/WA7iSlzF38pFxp2DbM+PV
kQYxFKHgyL4OsuT+tT1Zcm9eItO7MCCOjXFRnRiEqM7NVODBCvGRLsceOXQdcfb2
yJwaci+dU4jWQBXbiNuoGSIxPeaWG/BHaExtvONnq9EivLgcgh4C42/ia6qd6EXb
ObqlWatq3CY0MaSEuCoYymLum+apR4YQMgeMqqtzasi7qxTBnsw9zcjb6lwLUNIq
0/RZ9bqSPA5IJG/o2LS6hf7/P2i4jzHr7ROahnVUEkfkFqglI17wKLBjrPXe5WT4
S53rTkL/HRfD6ZrSWKvQhJNR7Tu5fXouOizuVinzTcQn9oUo3JMdQN42/5cctVvW
WztnSSWfpJ/0qIRELLPRPndvrnIm40+wpo8GNw8CSd/Pg4IILXJzFsc8BFLDuAVG
Y8KmRQRNXnq9q3dfngwB9fSWKRtufXPktpUfnGKn/2cyFID54Qj35RTFu1Z6ZdzF
tRdheIVoJHoY1eDnJLEH
=v98p
-----END PGP SIGNATURE-----


Current thread: