Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:4191-1

Опубликовано: 27 дек. 2021
Источник: suse-cvrf

Описание

Security update for net-snmp

This update for net-snmp fixes the following issues:

  • CVE-2020-15862: Make extended MIB read-only (bsc#1174961)

Список пакетов

SUSE Linux Enterprise High Performance Computing 15-ESPOS
libsnmp30-5.7.3-7.13.1
net-snmp-5.7.3-7.13.1
net-snmp-devel-5.7.3-7.13.1
perl-SNMP-5.7.3-7.13.1
snmp-mibs-5.7.3-7.13.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
libsnmp30-5.7.3-7.13.1
net-snmp-5.7.3-7.13.1
net-snmp-devel-5.7.3-7.13.1
perl-SNMP-5.7.3-7.13.1
snmp-mibs-5.7.3-7.13.1
SUSE Linux Enterprise Server 15-LTSS
libsnmp30-5.7.3-7.13.1
net-snmp-5.7.3-7.13.1
net-snmp-devel-5.7.3-7.13.1
perl-SNMP-5.7.3-7.13.1
snmp-mibs-5.7.3-7.13.1
SUSE Linux Enterprise Server for SAP Applications 15
libsnmp30-5.7.3-7.13.1
net-snmp-5.7.3-7.13.1
net-snmp-devel-5.7.3-7.13.1
perl-SNMP-5.7.3-7.13.1
snmp-mibs-5.7.3-7.13.1

Описание

Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libsnmp30-5.7.3-7.13.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:net-snmp-5.7.3-7.13.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:net-snmp-devel-5.7.3-7.13.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:perl-SNMP-5.7.3-7.13.1

Ссылки