Summary: | <net-analyzer/net-snmp-5.8.1_pre1: Multiple vulnerabilities (CVE-2020-{15861,15862}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | David Denoncin <gentoo> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | netmon |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B1 [glsa+ cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | |||
Bug Blocks: | 729610 |
Description
David Denoncin
2020-07-31 22:27:59 UTC
* CVE-2020-15862 Description: "Net-SNMP through 5.7.3 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root." Patch: https://github.com/net-snmp/net-snmp/commit/77f6c60f57dba0aaea5d8ef1dd94bcd0c8e6d205 (which is in 5.8.1_pre1) Tree seems clean so just need to glsa. This issue was resolved and addressed in GLSA 202008-12 at https://security.gentoo.org/glsa/202008-12 by GLSA coordinator Sam James (sam_c). |