Описание
Security update for net-snmp
This update for net-snmp fixes the following issues:
- CVE-2020-15862: Make extended MIB read-only (bsc#1174961)
Список пакетов
SUSE Linux Enterprise High Performance Computing 15-ESPOS
libsnmp30-5.7.3-7.13.1
net-snmp-5.7.3-7.13.1
net-snmp-devel-5.7.3-7.13.1
perl-SNMP-5.7.3-7.13.1
snmp-mibs-5.7.3-7.13.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
libsnmp30-5.7.3-7.13.1
net-snmp-5.7.3-7.13.1
net-snmp-devel-5.7.3-7.13.1
perl-SNMP-5.7.3-7.13.1
snmp-mibs-5.7.3-7.13.1
SUSE Linux Enterprise Server 15-LTSS
libsnmp30-5.7.3-7.13.1
net-snmp-5.7.3-7.13.1
net-snmp-devel-5.7.3-7.13.1
perl-SNMP-5.7.3-7.13.1
snmp-mibs-5.7.3-7.13.1
SUSE Linux Enterprise Server for SAP Applications 15
libsnmp30-5.7.3-7.13.1
net-snmp-5.7.3-7.13.1
net-snmp-devel-5.7.3-7.13.1
perl-SNMP-5.7.3-7.13.1
snmp-mibs-5.7.3-7.13.1
Ссылки
- Link for SUSE-SU-2021:4191-1
- E-Mail link for SUSE-SU-2021:4191-1
- SUSE Security Ratings
- SUSE Bug 1152968
- SUSE Bug 1174961
- SUSE CVE CVE-2020-15862 page
Описание
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:libsnmp30-5.7.3-7.13.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:net-snmp-5.7.3-7.13.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:net-snmp-devel-5.7.3-7.13.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:perl-SNMP-5.7.3-7.13.1
Ссылки
- CVE-2020-15862
- SUSE Bug 1174961
- SUSE Bug 1193875
- SUSE Bug 1196341