Security Advisory net-snmp security update

Advisory: RHSA-2004:023-01
Type: Security Advisory
Severity: Moderate
Issued on: 2004-01-15
Last updated on: 2004-01-15
Affected Products: Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2003-0935

Details

Updated Net-SNMP packages are available to correct a security vulnerability
and other bugs.

The Net-SNMP project includes various Simple Network Management Protocol
(SNMP) tools.

A security issue in Net-SNMP versions before 5.0.9 could allow an existing
user/community to gain access to data in MIB objects that were explicitly
excluded from their view. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0935 to this issue.

Users of Net-SNMP are advised to upgrade to these errata packages containing
Net-SNMP 5.0.9 which is not vulnerable to this issue. In addition,
Net-SNMP 5.0.9 fixes a number of other minor bugs.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Enterprise Linux AS (v. 3)

SRPMS:
net-snmp-5.0.9-2.30E.1.src.rpm
File outdated by:  RHSA-2009:1124
    848359f597ebf1a083501cf3c80532fc
 
IA-32:
net-snmp-5.0.9-2.30E.1.i386.rpm
File outdated by:  RHSA-2009:1124
    79ca1bebbf32c8a2aff71853ade36296
net-snmp-devel-5.0.9-2.30E.1.i386.rpm
File outdated by:  RHSA-2009:1124
    e7f28a7da234bb6ee2d6f55fda30107c
net-snmp-utils-5.0.9-2.30E.1.i386.rpm
File outdated by:  RHSA-2009:1124
    bec698635f32742031ebbce4db92f3cd
 
IA-64:
net-snmp-5.0.9-2.30E.1.ia64.rpm
File outdated by:  RHSA-2009:1124
    c57836c4bc29c2e9a94fcdace13b8352
net-snmp-devel-5.0.9-2.30E.1.ia64.rpm
File outdated by:  RHSA-2009:1124
    07f6ddd369d38551baa5e8141c98826a
net-snmp-utils-5.0.9-2.30E.1.ia64.rpm
File outdated by:  RHSA-2009:1124
    a01100bc7d51a32fa381df866297ac88
 
PPC:
net-snmp-5.0.9-2.30E.1.ppc.rpm
File outdated by:  RHSA-2009:1124
    64a3c07f70292fb7193ddae92523166b
net-snmp-devel-5.0.9-2.30E.1.ppc.rpm
File outdated by:  RHSA-2009:1124
    2cf2fe5acb2ada50af46255aca7cd9be
net-snmp-utils-5.0.9-2.30E.1.ppc.rpm
File outdated by:  RHSA-2009:1124
    2600ca9c62e1556b1658e28f99d8c469
 
s390:
net-snmp-5.0.9-2.30E.1.s390.rpm
File outdated by:  RHSA-2009:1124
    f4cf5b5792fade070b5be837ea40be12
net-snmp-devel-5.0.9-2.30E.1.s390.rpm
File outdated by:  RHSA-2009:1124
    08468bec94947f9f44a33b72802bdfc4
net-snmp-utils-5.0.9-2.30E.1.s390.rpm
File outdated by:  RHSA-2009:1124
    a7eda2441bbc09e163ed13b4db6932f8
 
s390x:
net-snmp-5.0.9-2.30E.1.s390x.rpm
File outdated by:  RHSA-2009:1124
    33acbbd4932fccc522efd0fb5d0adb1e
net-snmp-devel-5.0.9-2.30E.1.s390x.rpm
File outdated by:  RHSA-2009:1124
    a62f73ac880b56ad51848c2b3f08b0f1
net-snmp-utils-5.0.9-2.30E.1.s390x.rpm
File outdated by:  RHSA-2009:1124
    e5f048af0fae73025b543ded7445fe61
 
x86_64:
net-snmp-5.0.9-2.30E.1.x86_64.rpm
File outdated by:  RHSA-2009:1124
    7752bcd3f4eeb840da54031c5967234f
net-snmp-devel-5.0.9-2.30E.1.x86_64.rpm
File outdated by:  RHSA-2009:1124
    4a7dde3020926893ace9ab8744021d67
net-snmp-utils-5.0.9-2.30E.1.x86_64.rpm
File outdated by:  RHSA-2009:1124
    1b2d25bfb90fbd213ddbeecea128d2c1
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
net-snmp-5.0.9-2.30E.1.src.rpm
File outdated by:  RHSA-2009:1124
    848359f597ebf1a083501cf3c80532fc
 
IA-32:
net-snmp-5.0.9-2.30E.1.i386.rpm
File outdated by:  RHSA-2009:1124
    79ca1bebbf32c8a2aff71853ade36296
net-snmp-devel-5.0.9-2.30E.1.i386.rpm
File outdated by:  RHSA-2009:1124
    e7f28a7da234bb6ee2d6f55fda30107c
net-snmp-utils-5.0.9-2.30E.1.i386.rpm
File outdated by:  RHSA-2009:1124
    bec698635f32742031ebbce4db92f3cd
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
net-snmp-5.0.9-2.30E.1.src.rpm
File outdated by:  RHSA-2009:1124
    848359f597ebf1a083501cf3c80532fc
 
IA-32:
net-snmp-5.0.9-2.30E.1.i386.rpm
File outdated by:  RHSA-2009:1124
    79ca1bebbf32c8a2aff71853ade36296
net-snmp-devel-5.0.9-2.30E.1.i386.rpm
File outdated by:  RHSA-2009:1124
    e7f28a7da234bb6ee2d6f55fda30107c
net-snmp-utils-5.0.9-2.30E.1.i386.rpm
File outdated by:  RHSA-2009:1124
    bec698635f32742031ebbce4db92f3cd
 
IA-64:
net-snmp-5.0.9-2.30E.1.ia64.rpm
File outdated by:  RHSA-2009:1124
    c57836c4bc29c2e9a94fcdace13b8352
net-snmp-devel-5.0.9-2.30E.1.ia64.rpm
File outdated by:  RHSA-2009:1124
    07f6ddd369d38551baa5e8141c98826a
net-snmp-utils-5.0.9-2.30E.1.ia64.rpm
File outdated by:  RHSA-2009:1124
    a01100bc7d51a32fa381df866297ac88
 
x86_64:
net-snmp-5.0.9-2.30E.1.x86_64.rpm
File outdated by:  RHSA-2009:1124
    7752bcd3f4eeb840da54031c5967234f
net-snmp-devel-5.0.9-2.30E.1.x86_64.rpm
File outdated by:  RHSA-2009:1124
    4a7dde3020926893ace9ab8744021d67
net-snmp-utils-5.0.9-2.30E.1.x86_64.rpm
File outdated by:  RHSA-2009:1124
    1b2d25bfb90fbd213ddbeecea128d2c1
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

109622 - net-snmp unauthorised access to mibs


References


Keywords

ucd-snmp


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/