<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>225105</bug_id>
          <alias>CVE-2008-0960</alias>
          <creation_ts>2008-06-06 10:50 0000</creation_ts>
          <short_desc>net-analyzer/net-snmp &lt;5.4.1.1 truncated HMAC authentication code (CVE-2008-0960)</short_desc>
          <delta_ts>2008-08-06 00:30:47 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.ocert.org/advisories/ocert-2008-006.html</bug_file_loc>
          <status_whiteboard>B3 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>227603</dependson>
          <blocked>222265</blocked>
          
          <everconfirmed>1</everconfirmed>
          <reporter>vorlon@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>arm@gentoo.org</cc>
    
    <cc>netmon@gentoo.org</cc>
    
    <cc>s390@gentoo.org</cc>
    
    <cc>sh@gentoo.org</cc>
    
    <cc>wolf31o2@wolf31o2.org</cc>

      

      
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2008-06-06 10:50:14 0000</bug_when>
            <thetext>** Please note that this issue is confidential at the moment and no information
should be disclosed until it is made public **

We have been contacted by CERT/CC about the following issue:
&lt;quote&gt;
According to net-snmp project:

&quot;The quick technical summary is that the SNMPv3 packet contains a
truncated HMAC authentication code.  The author that wrote the code
very very long ago to check that HMAC code used the length of the
packet&apos;s version of the HMAC code to do the check.  Thus if you send a
single byte HMAC code, it&apos;ll only check it against the first byte of
HMAC output.  Thus it&apos;s fairly easy to spoof an authenticated SNMPv3
packet.
&lt;/quote&gt;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2008-06-06 10:51:54 0000</bug_when>
            <thetext>Created an attachment (id=155709)
patch for CVE-2008-0960

</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vorlon@gentoo.org</who>
            <bug_when>2008-06-06 10:53:44 0000</bug_when>
            <thetext>pva/falco/vapier since you are all in netmon herd anyways, please prepare an ebuild with the patch and attach it here.

Do not commit anything to the tree until this issue is made public.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-06-06 19:26:32 0000</bug_when>
            <thetext>Created an attachment (id=155745)
net-snmp-5.4.1-CVE-2008-0960.patch

Thank you Matthias. Attached patch was corrupted one. Attaching correct one.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-06-06 19:30:09 0000</bug_when>
            <thetext>BTW, I don&apos;t see any rush with this security fix. I&apos;m going to bump net-snmp now to fix quite a number of bugs, after that I&apos;d like to have at least 2 weeks for feedback on patches I&apos;ve backported from upstream and only after that stabilize this package... Also we have another security fix for this package in queue so it&apos;s better to test stabilize them together, I suppose.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-10 01:07:25 0000</bug_when>
            <thetext>Now public via URL.
&quot;Fixed version:
Net-SNMP &gt;= 5.4.1.1, &gt;= 5.3.2.1, &gt;= 5.2.4.1&quot;

Peter, take the time you want to test this issue, </thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>pva@gentoo.org</who>
            <bug_when>2008-06-21 06:40:30 0000</bug_when>
            <thetext>5.4.1.1 is ready to go stable together with autoconf-2.61-r2 (which should be stabilized in bug 227603).

Target keywords:
net-analyzer/net-snmp-5.4.1.1: alpha amd64 arm hppa ia64 ppc64 ppc s390 sh sparc x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2008-06-21 09:25:10 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-21 13:49:55 0000</bug_when>
            <thetext>pva, I&apos;m adding release@, or did you handle this yourself already?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2008-06-21 19:39:10 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>maekke@gentoo.org</who>
            <bug_when>2008-06-22 11:08:45 0000</bug_when>
            <thetext>amd64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2008-06-22 18:11:38 0000</bug_when>
            <thetext>alpha/ia64/sparc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2008-06-23 17:14:05 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ranger@gentoo.org</who>
            <bug_when>2008-06-23 19:00:07 0000</bug_when>
            <thetext>ppc done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-06-24 01:05:00 0000</bug_when>
            <thetext>GLSA vote, YES for me.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>keytoaster@gentoo.org</who>
            <bug_when>2008-07-02 11:15:08 0000</bug_when>
            <thetext>YES too, filing request.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wolf31o2@gentoo.org</who>
            <bug_when>2008-08-01 17:49:17 0000</bug_when>
            <thetext>2008.0 is out, so no need to keep release on the CC list.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>rbu@gentoo.org</who>
            <bug_when>2008-08-06 00:30:47 0000</bug_when>
            <thetext>GLSA 200808-02</thetext>
          </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>155709</attachid>
            <date>2008-06-06 10:51 0000</date>
            <desc>patch for CVE-2008-0960</desc>
            <filename>CVE-2008-0960.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIG5ldC1zbm1wLTUuNC4xL3NubXBsaWIvc2NhcGkuYyAgICAgIDIwMDYtMDktMTUgMDU6NDc6
MDEuMDAwMDAwMDAwIC0wNzAwCisrKyBuZXQtc25tcC01LjQuMS4xL3NubXBsaWIvc2NhcGkuYyAg
ICAyMDA4LTA1LTEzIDE3OjQzOjE3LjAwMDAwMDAwMCAtMDcwMApAQCAtNTYzLDYgKzU2MywxMCBA
QAoKfQoKCisgICAgaWYgKG1hY2xlbiAhPSBVU01fTUQ1X0FORF9TSEFfQVVUSF9MRU4pIHsKKyAg
ICAgICAgUVVJVEZVTihTTk1QRVJSX0dFTkVSUiwgc2NfY2hlY2tfa2V5ZWRfaGFzaF9xdWl0KTsK
KyAgICB9CisKLyoKKiBHZW5lcmF0ZSBhIGZ1bGwgaGFzaCBvZiB0aGUgbWVzc2FnZSwgdGhlbiBj
b21wYXJlCiogdGhlIHJlc3VsdCB3aXRoIHRoZSBnaXZlbiBNQUMgd2hpY2ggbWF5IHNob3J0ZXIg
dGhhbgo=
</data>        

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>155745</attachid>
            <date>2008-06-06 19:26 0000</date>
            <desc>net-snmp-5.4.1-CVE-2008-0960.patch</desc>
            <filename>net-snmp-5.4.1-CVE-2008-0960.patch</filename>
            <type>text/plain</type>
            <data encoding="base64">LS0tIHNubXBsaWIvc2NhcGkuYwkyMDA4LTA2LTA2IDE1OjQ0OjMwICswMDAwCisrKyBzbm1wbGli
L3NjYXBpLmMJMjAwOC0wNi0wNiAxNTo0NzoxNiArMDAwMApAQCAtNTYzLDYgKzU2MywxMCBAQAog
ICAgIH0KIAogCisgICAgaWYgKG1hY2xlbiAhPSBVU01fTUQ1X0FORF9TSEFfQVVUSF9MRU4pIHsK
KyAgICAgICAgUVVJVEZVTihTTk1QRVJSX0dFTkVSUiwgc2NfY2hlY2tfa2V5ZWRfaGFzaF9xdWl0
KTsKKyAgICB9CisKICAgICAvKgogICAgICAqIEdlbmVyYXRlIGEgZnVsbCBoYXNoIG9mIHRoZSBt
ZXNzYWdlLCB0aGVuIGNvbXBhcmUKICAgICAgKiB0aGUgcmVzdWx0IHdpdGggdGhlIGdpdmVuIE1B
QyB3aGljaCBtYXkgc2hvcnRlciB0aGFuCgo=
</data>        

          </attachment>
    </bug>

</bugzilla>