Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 245306 (CVE-2008-4309) - net-analyzer/net-snmp <5.4.2.1: getbulk Heap Overflow (CVE-2008-4309)
Summary: net-analyzer/net-snmp <5.4.2.1: getbulk Heap Overflow (CVE-2008-4309)
Status: RESOLVED FIXED
Alias: CVE-2008-4309
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Highest minor (vote)
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard: B3 [glsa]
Keywords:
: 237172 (view as bug list)
Depends on:
Blocks:
 
Reported: 2008-11-02 19:17 UTC by Stefan Behte (RETIRED)
Modified: 2009-01-21 22:36 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-11-02 19:17:48 UTC
CVE-2008-4309 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4309):
  The getbulk code in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3,
  and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of
  service (crash) via vectors related to the number of responses or
  repeats.
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-10 15:56:00 UTC
netmon, are you still alive? ;P
I'm just curious if someone works on this, our timeline for B4 is 20 days.
Comment 3 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-12 19:02:00 UTC
POC: http://www.milw0rm.com/exploits/7100
Comment 4 Tobias Scherbaum (RETIRED) gentoo-dev 2008-11-12 20:47:59 UTC
(In reply to comment #2)
> netmon, are you still alive? ;P
> I'm just curious if someone works on this, our timeline for B4 is 20 days.
> 

if noone else bumps within the next days i'll take a look at it during the weekend.
Comment 5 Stefan Behte (RETIRED) gentoo-dev Security 2008-11-12 21:45:16 UTC
Thanks Tobi!

Re-rating B0, severity blocker: the CVE does not mention it, but securityfocus and the exploit say that remote code execution is possible - and snmpd runs as root!
Comment 6 Jeroen Roovers (RETIRED) gentoo-dev 2008-11-13 17:47:23 UTC
# ChangeLog for net-analyzer/net-snmp
# Copyright 2002-2008 Gentoo Foundation; Distributed under the GPL v2
# $Header: /var/cvsroot/gentoo-x86/net-analyzer/net-snmp/ChangeLog,v 1.181 2008/11/13 17:46:48 jer Exp $

*net-snmp-5.4.2.1 (13 Nov 2008)

  13 Nov 2008; Jeroen Roovers <jer@gentoo.org> +net-snmp-5.4.2.1.ebuild:
  Version bump (bug #245306).
Comment 7 Christian Hoffmann (RETIRED) gentoo-dev 2008-11-13 17:52:37 UTC
Arches, please test and mark stable:
  =net-analyzer/net-snmp-5.4.2.1

Target keywords: alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86


(Revmoing versions from summary which don't affect us)
Comment 8 Jeroen Roovers (RETIRED) gentoo-dev 2008-11-13 18:05:40 UTC
Stable for HPPA.
Comment 9 Tobias Scherbaum (RETIRED) gentoo-dev 2008-11-14 20:54:26 UTC
ppc stable
Comment 10 Markus Meier gentoo-dev 2008-11-15 10:27:02 UTC
amd64/x86 stable
Comment 11 Markus Rothe (RETIRED) gentoo-dev 2008-11-15 12:52:31 UTC
ppc64 stable
Comment 12 Raúl Porcel (RETIRED) gentoo-dev 2008-11-15 17:36:19 UTC
alpha/arm/ia64/sparc stable
Comment 13 Raúl Porcel (RETIRED) gentoo-dev 2009-01-01 17:37:44 UTC
s390/sh stable
Comment 14 Stefan Behte (RETIRED) gentoo-dev Security 2009-01-10 04:14:45 UTC
GLSA was NOT filed yet!
Comment 15 Pierre-Yves Rofes (RETIRED) gentoo-dev 2009-01-11 17:57:55 UTC
(In reply to comment #14)
> GLSA was NOT filed yet!
> 

fixed now.
Comment 16 Pierre-Yves Rofes (RETIRED) gentoo-dev 2009-01-12 22:12:19 UTC
(In reply to comment #5)
> Thanks Tobi!
> 
> Re-rating B0, severity blocker: the CVE does not mention it, but securityfocus
> and the exploit say that remote code execution is possible - and snmpd runs as
> root!
> 
This exploit is for CVE-2008-2292... rerating B3.
Comment 17 Jeroen Roovers (RETIRED) gentoo-dev 2009-01-15 05:07:00 UTC
*** Bug 237172 has been marked as a duplicate of this bug. ***
Comment 18 Pierre-Yves Rofes (RETIRED) gentoo-dev 2009-01-21 22:36:13 UTC
GLSA 200901-15