Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 198346
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 198346 depends on: 191550 Show dependency tree
Bug 198346 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-11-07 12:25 0000
CVE-2007-5846 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5846):
  The SNMP agent in net-snmp 5.4.1 and earlier allows remote attackers to cause
  a denial of service (CPU and memory consumption) via a GETBULK request with a
  large max-repeaters value.

------- Comment #1 From Robert Buchholz 2007-11-07 12:27:16 0000 -------
Netmon, please advise.

------- Comment #2 From Martin Jackson (RETIRED) 2007-11-08 01:09:46 0000 -------
I don't think the CVE entry is correct.  5.4.1 had the patch in question
applied already.  (Man snmpd.conf; you see the maxGetbulkRepeats and
maxGetbulkResponses tunables, which are part of the patch referenced), also
ds_agent.h file, etc).

I'm sure 5.3.1 is vulnerable.  It was released long before the patch was
committed.

I think we should stable 5.4.1-r1 and clean up the other releases.  I don't
think we need to carry that many versions of net-snmp in the tree.

Any objections?

------- Comment #3 From Robert Buchholz 2007-11-08 03:17:45 0000 -------
(In reply to comment #2)
> I don't think the CVE entry is correct.  5.4.1 had the patch in question
> applied already.  (Man snmpd.conf; you see the maxGetbulkRepeats and
> maxGetbulkResponses tunables, which are part of the patch referenced), also
> ds_agent.h file, etc).

5.4 is stable right now, is it affected?

------- Comment #4 From Martin Jackson (RETIRED) 2007-11-08 03:30:38 0000 -------
> 5.4 is stable right now, is it affected?

Yes, it is.  The maxreps patch does apply cleanly on that version, though.

I could do a 5.4-r1 with the patch.  5.4.1 is a bit more complex to stable as
it introduced python bindings, which require a dep on MIPS to be stabled first
(requested, but not yet done).

------- Comment #5 From Sune Kloppenborg Jeppesen 2007-11-08 06:46:57 0000 -------
Martin it's up to you what fixed version to stable, just we get one to stable:)

------- Comment #6 From Jeroen Roovers 2007-11-08 07:02:35 0000 -------
Er, so the target is net-analyzer/net-snmp-5.4.1-r1 now?

------- Comment #7 From Sune Kloppenborg Jeppesen 2007-11-08 07:20:32 0000 -------
Sorry for the spam arches. I forgot to remove you from CC when I discovered
there were no clear stable candidate. UnCCing arches for now.

Netmon please advise.

------- Comment #8 From Martin Jackson (RETIRED) 2007-11-08 12:55:09 0000 -------
> Netmon please advise.
> 

I think we're better off stabling 5.4.1-r1, but we need to keyword/stable
dev-python/setuptools on mips first (191550).  Can someone from mips@ help with
that?

If that's not viable (i.e. there's some reason we can't keyword and stable
setuptools on mips), I have committed a 5.4-r1 with the maxreps patch.

Thanks, Marty

------- Comment #9 From Robert Buchholz 2007-11-08 16:59:08 0000 -------
MIPS, please see the blocker of this bug first.

Arches, please test and mark stable net-analyzer/net-snmp-5.4.1-r1.
Target keywords : "alpha amd64 arm hppa ia64 mips ppc ppc64 s390 sh sparc x86"

------- Comment #10 From Markus Rothe 2007-11-08 19:37:11 0000 -------
ppc64 stable

------- Comment #11 From Dawid Węgliński 2007-11-09 14:50:31 0000 -------
x86 stable

------- Comment #12 From Raúl Porcel 2007-11-09 15:10:17 0000 -------
alpha/ia64/sparc stable

------- Comment #13 From Jeroen Roovers 2007-11-09 18:12:10 0000 -------
Stable for HPPA.

------- Comment #14 From Tobias Scherbaum 2007-11-13 19:54:59 0000 -------
ppc stable

------- Comment #15 From Chris Gianelloni (RETIRED) 2007-11-14 01:07:54 0000 -------
amd64 done

------- Comment #16 From Robert Buchholz 2007-11-14 01:30:45 0000 -------
Vote is open.

Martin, do I see correctly that this vulnerability can be exploited by
authenticated users / hosts in usual setups? Or is the SNMP agent designed to
be connected publically?

------- Comment #17 From Robert Buchholz 2007-11-16 00:15:01 0000 -------
According to RedHat this is a DoS for unauthenticated users.

Voting YES.

------- Comment #18 From Pierre-Yves Rofes 2007-11-18 22:35:24 0000 -------
yes too, request filed.

------- Comment #19 From Joshua Kinard 2007-11-19 06:21:07 0000 -------
Unstable on mips.

------- Comment #20 From Pierre-Yves Rofes 2007-11-20 22:07:24 0000 -------
GLSA 200711-31

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug