int(3587)

Boletines de Vulnerabilidades


Denegación de servicio en net-snmp

Clasificación de la vulnerabilidad

Propiedad Valor
Nivel de Confianza Oficial
Impacto Denegación de Servicio
Dificultad Experto
Requerimientos del atacante Acceso remoto sin cuenta a un servicio estandar

Información sobre el sistema

Propiedad Valor
Fabricante afectado GNU/Linux
Software afectado net-snmp < 5.4.1

Descripción

Se ha encontrado una vulnerabilidad en el agente SNMP en net-snmp en las versiones anteriores a la 5.4.1. La vulnerabilidad reside en un error no especificado.

Un atacante remoto podría causar una denegación de servicio mediante una petición GETBULK con un valor grande en max-repeaters.

Solución



Actualización de software

Red Hat (RHSA-2007:1045-3)
RHEL Desktop Workstation (v. 5 client)
Red Hat Desktop (v. 3)
Red Hat Desktop (v. 4)
Red Hat Enterprise Linux (v. 5 server)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux AS (v. 4)
Red Hat Enterprise Linux Desktop (v. 5 client)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux ES (v. 4)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Enterprise Linux WS (v. 4)
https://rhn.redhat.com/

Mandriva (MDKSA-2007:225)

Corporate Server 3.0
X86
corporate/3.0/i586/libnet-snmp5-5.1-7.3.C30mdk.i586.rpm
corporate/3.0/i586/libnet-snmp5-devel-5.1-7.3.C30mdk.i586.rpm
corporate/3.0/i586/libnet-snmp5-static-devel-5.1-7.3.C30mdk.i586.rpm
corporate/3.0/i586/net-snmp-5.1-7.3.C30mdk.i586.rpm
corporate/3.0/i586/net-snmp-mibs-5.1-7.3.C30mdk.i586.rpm
corporate/3.0/i586/net-snmp-trapd-5.1-7.3.C30mdk.i586.rpm
corporate/3.0/i586/net-snmp-utils-5.1-7.3.C30mdk.i586.rpm
corporate/3.0/SRPMS/net-snmp-5.1-7.3.C30mdk.src.rpm
X86_64
corporate/3.0/x86_64/lib64net-snmp5-5.1-7.3.C30mdk.x86_64.rpm
corporate/3.0/x86_64/lib64net-snmp5-devel-5.1-7.3.C30mdk.x86_64.rpm
corporate/3.0/x86_64/lib64net-snmp5-static-devel-5.1-7.3.C30mdk.x86_64.rpm
corporate/3.0/x86_64/net-snmp-5.1-7.3.C30mdk.x86_64.rpm
corporate/3.0/x86_64/net-snmp-mibs-5.1-7.3.C30mdk.x86_64.rpm
corporate/3.0/x86_64/net-snmp-trapd-5.1-7.3.C30mdk.x86_64.rpm
corporate/3.0/x86_64/net-snmp-utils-5.1-7.3.C30mdk.x86_64.rpm
corporate/3.0/SRPMS/net-snmp-5.1-7.3.C30mdk.src.rpm

Multi Network Firewall 2.0
X86
mnf/2.0/i586/libnet-snmp5-5.1-7.3.M20mdk.i586.rpm
mnf/2.0/SRPMS/net-snmp-5.1-7.3.M20mdk.src.rpm

Mandriva Linux 2007
X86
2007.0/i586/libnet-snmp10-5.3.1-2.1mdv2007.0.i586.rpm
2007.0/i586/libnet-snmp10-devel-5.3.1-2.1mdv2007.0.i586.rpm
2007.0/i586/libnet-snmp10-static-devel-5.3.1-2.1mdv2007.0.i586.rpm
2007.0/i586/net-snmp-5.3.1-2.1mdv2007.0.i586.rpm
2007.0/i586/net-snmp-mibs-5.3.1-2.1mdv2007.0.i586.rpm
2007.0/i586/net-snmp-trapd-5.3.1-2.1mdv2007.0.i586.rpm
2007.0/i586/net-snmp-utils-5.3.1-2.1mdv2007.0.i586.rpm
2007.0/i586/perl-NetSNMP-5.3.1-2.1mdv2007.0.i586.rpm
2007.0/SRPMS/net-snmp-5.3.1-2.1mdv2007.0.src.rpm
X86_64
2007.0/x86_64/lib64net-snmp10-5.3.1-2.1mdv2007.0.x86_64.rpm
2007.0/x86_64/lib64net-snmp10-devel-5.3.1-2.1mdv2007.0.x86_64.rpm
2007.0/x86_64/lib64net-snmp10-static-devel-5.3.1-2.1mdv2007.0.x86_64.rpm
2007.0/x86_64/net-snmp-5.3.1-2.1mdv2007.0.x86_64.rpm
2007.0/x86_64/net-snmp-mibs-5.3.1-2.1mdv2007.0.x86_64.rpm
2007.0/x86_64/net-snmp-trapd-5.3.1-2.1mdv2007.0.x86_64.rpm
2007.0/x86_64/net-snmp-utils-5.3.1-2.1mdv2007.0.x86_64.rpm
2007.0/x86_64/perl-NetSNMP-5.3.1-2.1mdv2007.0.x86_64.rpm
2007.0/SRPMS/net-snmp-5.3.1-2.1mdv2007.0.src.rpm

Corporate Server 4.0
X86
corporate/4.0/i586/libnet-snmp5-5.2.1.2-5.1.20060mlcs4.i586.rpm
corporate/4.0/i586/libnet-snmp5-devel-5.2.1.2-5.1.20060mlcs4.i586.rpm
corporate/4.0/i586/libnet-snmp5-static-devel-5.2.1.2-5.1.20060mlcs4.i586.rpm
corporate/4.0/i586/net-snmp-5.2.1.2-5.1.20060mlcs4.i586.rpm
corporate/4.0/i586/net-snmp-mibs-5.2.1.2-5.1.20060mlcs4.i586.rpm
corporate/4.0/i586/net-snmp-trapd-5.2.1.2-5.1.20060mlcs4.i586.rpm
corporate/4.0/i586/net-snmp-utils-5.2.1.2-5.1.20060mlcs4.i586.rpm
corporate/4.0/i586/perl-NetSNMP-5.2.1.2-5.1.20060mlcs4.i586.rpm
corporate/4.0/SRPMS/net-snmp-5.2.1.2-5.1.20060mlcs4.src.rpm
X86_64
corporate/4.0/x86_64/lib64net-snmp5-5.2.1.2-5.1.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/lib64net-snmp5-devel-5.2.1.2-5.1.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/lib64net-snmp5-static-devel-5.2.1.2-5.1.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/net-snmp-5.2.1.2-5.1.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/net-snmp-mibs-5.2.1.2-5.1.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/net-snmp-trapd-5.2.1.2-5.1.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/net-snmp-utils-5.2.1.2-5.1.20060mlcs4.x86_64.rpm
corporate/4.0/x86_64/perl-NetSNMP-5.2.1.2-5.1.20060mlcs4.x86_64.rpm
corporate/4.0/SRPMS/net-snmp-5.2.1.2-5.1.20060mlcs4.src.rpm

Mandriva Linux 2007.1
X86
2007.1/i586/libnet-snmp10-5.3.1-3.1mdv2007.1.i586.rpm
2007.1/i586/libnet-snmp10-devel-5.3.1-3.1mdv2007.1.i586.rpm
2007.1/i586/libnet-snmp10-static-devel-5.3.1-3.1mdv2007.1.i586.rpm
2007.1/i586/net-snmp-5.3.1-3.1mdv2007.1.i586.rpm
2007.1/i586/net-snmp-mibs-5.3.1-3.1mdv2007.1.i586.rpm
2007.1/i586/net-snmp-trapd-5.3.1-3.1mdv2007.1.i586.rpm
2007.1/i586/net-snmp-utils-5.3.1-3.1mdv2007.1.i586.rpm
2007.1/i586/perl-NetSNMP-5.3.1-3.1mdv2007.1.i586.rpm
2007.1/SRPMS/net-snmp-5.3.1-3.1mdv2007.1.src.rpm
X86_64
2007.1/x86_64/lib64net-snmp10-5.3.1-3.1mdv2007.1.x86_64.rpm
2007.1/x86_64/lib64net-snmp10-devel-5.3.1-3.1mdv2007.1.x86_64.rpm
2007.1/x86_64/lib64net-snmp10-static-devel-5.3.1-3.1mdv2007.1.x86_64.rpm
2007.1/x86_64/net-snmp-5.3.1-3.1mdv2007.1.x86_64.rpm
2007.1/x86_64/net-snmp-mibs-5.3.1-3.1mdv2007.1.x86_64.rpm
2007.1/x86_64/net-snmp-trapd-5.3.1-3.1mdv2007.1.x86_64.rpm
2007.1/x86_64/net-snmp-utils-5.3.1-3.1mdv2007.1.x86_64.rpm
2007.1/x86_64/perl-NetSNMP-5.3.1-3.1mdv2007.1.x86_64.rpm
2007.1/SRPMS/net-snmp-5.3.1-3.1mdv2007.1.src.rpm

Suse Linux
Las actualizaciones pueden descargarse mediante YAST o del servidor FTP oficial de Suse Linux.

Ubuntu (USN-564-1)

Ubuntu 6.06 LTS
snmpd / patch 5.2.1.2-4ubuntu2.2

Ubuntu 6.10
snmpd / patch 5.2.2-5ubuntu1.1

Ubuntu 7.04
snmpd / patch 5.2.3-4ubuntu1.1

Ubuntu 7.10
snmpd / patch 5.3.1-6ubuntu2.1

Debian (DSA-1483-1)

Debian Linux 4.0
Source
http://security.debian.org/pool/updates/main/n/net-snmp/net-snmp_5.2.3-7etch2.diff.gz
http://security.debian.org/pool/updates/main/n/net-snmp/net-snmp_5.2.3-7etch2.dsc
http://security.debian.org/pool/updates/main/n/net-snmp/net-snmp_5.2.3.orig.tar.gz
Arquitectura independiente
http://security.debian.org/pool/updates/main/n/net-snmp/tkmib_5.2.3-7etch2_all.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp-base_5.2.3-7etch2_all.deb
alpha (DEC Alpha)
http://security.debian.org/pool/updates/main/n/net-snmp/snmpd_5.2.3-7etch2_alpha.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmp_5.2.3-7etch2_alpha.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9_5.2.3-7etch2_alpha.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9-dev_5.2.3-7etch2_alpha.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp-perl_5.2.3-7etch2_alpha.deb
amd64 (AMD x86_64 (AMD64))
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9_5.2.3-7etch2_amd64.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmpd_5.2.3-7etch2_amd64.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmp_5.2.3-7etch2_amd64.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9-dev_5.2.3-7etch2_amd64.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp-perl_5.2.3-7etch2_amd64.deb
arm (ARM)
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9_5.2.3-7etch2_arm.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmpd_5.2.3-7etch2_arm.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9-dev_5.2.3-7etch2_arm.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmp_5.2.3-7etch2_arm.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp-perl_5.2.3-7etch2_arm.deb
i386 (Intel ia32)
http://security.debian.org/pool/updates/main/n/net-snmp/snmpd_5.2.3-7etch2_i386.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp-perl_5.2.3-7etch2_i386.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9_5.2.3-7etch2_i386.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmp_5.2.3-7etch2_i386.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9-dev_5.2.3-7etch2_i386.deb
ia64 (Intel ia64)
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp-perl_5.2.3-7etch2_ia64.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmp_5.2.3-7etch2_ia64.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9-dev_5.2.3-7etch2_ia64.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmpd_5.2.3-7etch2_ia64.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9_5.2.3-7etch2_ia64.deb
mips (MIPS (Big Endian))
http://security.debian.org/pool/updates/main/n/net-snmp/snmp_5.2.3-7etch2_mips.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp-perl_5.2.3-7etch2_mips.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9_5.2.3-7etch2_mips.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9-dev_5.2.3-7etch2_mips.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmpd_5.2.3-7etch2_mips.deb
mipsel (MIPS (Little Endian))
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9_5.2.3-7etch2_mipsel.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp-perl_5.2.3-7etch2_mipsel.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9-dev_5.2.3-7etch2_mipsel.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmpd_5.2.3-7etch2_mipsel.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmp_5.2.3-7etch2_mipsel.deb
powerpc (PowerPC)
http://security.debian.org/pool/updates/main/n/net-snmp/snmp_5.2.3-7etch2_powerpc.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9-dev_5.2.3-7etch2_powerpc.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp-perl_5.2.3-7etch2_powerpc.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9_5.2.3-7etch2_powerpc.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmpd_5.2.3-7etch2_powerpc.deb
s390 (IBM S/390)
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp-perl_5.2.3-7etch2_s390.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmpd_5.2.3-7etch2_s390.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9_5.2.3-7etch2_s390.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9-dev_5.2.3-7etch2_s390.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmp_5.2.3-7etch2_s390.deb
sparc (Sun SPARC/UltraSPARC)
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp-perl_5.2.3-7etch2_sparc.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9_5.2.3-7etch2_sparc.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmp_5.2.3-7etch2_sparc.deb
http://security.debian.org/pool/updates/main/n/net-snmp/snmpd_5.2.3-7etch2_sparc.deb
http://security.debian.org/pool/updates/main/n/net-snmp/libsnmp9-dev_5.2.3-7etch2_sparc.deb

Identificadores estándar

Propiedad Valor
CVE CVE-2007-5846
BID 26378

Recursos adicionales

Red Hat Security Advisory (RHSA-2007:1045-3)
https://rhn.redhat.com/errata/RHSA-2007-1045.html

Mandriva Security Advisory (MDKSA-2007:225)
http://www.mandriva.com/security/advisories?name=MDKSA-2007:225

SUSE Security Summary Report (SUSE-SR:2007:025)
http://www.novell.com/linux/security/advisories/2007_25_sr.html

Ubuntu Security Advisory (USN-564-1)
http://www.ubuntu.com/usn/usn-564-1

Debian Security Advisory (DSA-1483-1)
http://lists.debian.org/debian-security-announce/debian-security-announce-2008/msg00046.html

Histórico de versiones

Versión Comentario Fecha
1.0 Aviso emitido 2007-11-19
1.1 Aviso emitido por Mandriva (MDKSA-2007:225) 2007-11-22
1.2 Aviso emitido por Suse (SUSE-SR:2007:025) 2007-12-10
1.3 Aviso emitido por Ubuntu (USN-564-1) 2008-01-11
1.4 Aviso emitido por Debian (DSA-1483-1) 2008-02-07

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT