English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Net-snmp TCP Wrapper Information Disclosure Vulnerability


Secunia ID

SA33884

CVE-ID

CVE-2008-6123

Release Date

12 Feb 2009

Last Change

19 Feb 2009

Criticality

Less Critical

Solution Status

Vendor Workaround

Software

Net-snmp 5.x

Where

From local network

Impact
Exposure of sensitive information

Vulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote.

Exposure of system information

Vulnerabilities where excessive information about the system (e.g. version numbers, running services, installation paths, and similar) are exposed and can be revealed from remote and in some cases locally.

Description

A vulnerability has been reported in Net-snmp, which can be exploited by malicious people to disclose sensitive information.

The vulnerability is caused due to an error when restricting access to the service via TCP wrappers. This can be exploited to disclose potentially sensitive information via SNMP requests, regardless of access restrictions in "hosts.allow" and "hosts.deny".

The vulnerability is reported in version 5.4.2.1. Other versions may also be affected.

Solution

Fixed in the SVN repository in revision 17367.

Reported by

Reported by Marcel Meckel via a Gentoo bug report.

Original Advisory

http://bugs.gentoo.org/show_bug.cgi?id=250429