The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when...
Vulnerability Description
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-6123
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openwall.com/lists/oss-security/2009/02/12/2
- http://www.openwall.com/lists/oss-security/2009/02/12/7
- http://bugs.gentoo.org/show_bug.cgi?id=250429
- https://bugzilla.redhat.com/show_bug.cgi?id=485211
- http://www.openwall.com/lists/oss-security/2009/02/12/4
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html
- http://www.redhat.com/support/errata/RHSA-2009-0295.html
- http://secunia.com/advisories/35685
- http://secunia.com/advisories/34499
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html
- http://secunia.com/advisories/35416
- http://net-snmp.svn.sourceforge.net/viewvc/net-snmp?view=rev&revision=17367
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10289
- http://www.securitytracker.com/id?1021921
- http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/trunk/net-snmp/snmplib/snmpUDPDomain.c?r1=17325&r2=17367&pathrev=17367
More from net-snmp
View All →Affected Vendor
net-snmp
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.