Описание
ELSA-2015-1385: net-snmp security and bug fix update (MODERATE)
[1:5.5-54.0.1]
- Add Oracle ACFS to hrStorage (John Haxby) [orabug 18510373]
[1:5.5-54]
- Quicker loading of IP-MIB::ipAddrTable (#1191393)
[1:5.5-53]
- Quicker loading of IP-MIB::ipAddressTable (#1191393)
[1:5.5-52]
- Fixed snmptrapd crash when '-OQ' parameter is used and invalid trap is received (#CVE-2014-3565)
[1:5.5-51]
- added faster caching into IP-MIB::ipNetToMediaTable (#789500)
- fixed compilation with '-Werror=format-security' (#1181994)
- added clear error message when port specified in 'clientaddrr' config option cannot be bound (#886468)
- fixed error check in IP-MIB::ipAddressTable (#1012430)
- fixed agentx client crash on failed response (#1023570)
- fixed dashes in net-snmp-config.h (#1034441)
- fixed crash on monitor trigger (#1050970)
- fixed 'netsnmp_assert 1 == new_val->high failed' message in system log (#1065210)
- fixed parsing of 64bit counters from SMUX subagents (#1069046)
- Fixed HOST-RESOURCES-MIB::hrProcessorTable on machines with >100 CPUs (#1070075)
- fixed net-snmp-create-v3-user to have the same content on 32 and 64bit installations (#1073544)
- fixed IPADDRESS value length in Python bindings (#1100099)
- fixed hrStorageTable to contain 31 bits integers (#1104293)
- fixed links to developer man pages (#1119567)
- fixed storageUseNFS functionality in hrStorageTable (#1125793)
- fixed netsnmp_set Python bindings call truncating at the first '\000' character (#1126914)
- fixed log level of SMUX messages (#1140234)
- use python/README to net-snmp-python subpackage (#1157373)
- fixed forwarding of traps with RequestID=0 in snmptrapd (#1146948)
- fixed typos in NET-SNMP-PASS-MIB and SMUX-MIB (#1162040)
- fixed close() overhead of extend commands (#1188295)
- fixed lmSensorsTable not reporting sensors with duplicate names (#967871)
- fixed hrDeviceTable with interfaces with large ifIndex (#1195547)
Обновленные пакеты
Oracle Linux 6
Oracle Linux x86_64
net-snmp
5.5-54.0.1.el6
net-snmp-devel
5.5-54.0.1.el6
net-snmp-libs
5.5-54.0.1.el6
net-snmp-perl
5.5-54.0.1.el6
net-snmp-python
5.5-54.0.1.el6
net-snmp-utils
5.5-54.0.1.el6
Oracle Linux i686
net-snmp
5.5-54.0.1.el6
net-snmp-devel
5.5-54.0.1.el6
net-snmp-libs
5.5-54.0.1.el6
net-snmp-perl
5.5-54.0.1.el6
net-snmp-python
5.5-54.0.1.el6
net-snmp-utils
5.5-54.0.1.el6
Связанные CVE
Связанные уязвимости
snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB file, as demonstrated by a NULL type in an ifMtu trap message.
snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB file, as demonstrated by a NULL type in an ifMtu trap message.
snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB file, as demonstrated by a NULL type in an ifMtu trap message.
snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is us ...
snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB file, as demonstrated by a NULL type in an ifMtu trap message.