#VU32864 Input validation error in Net-snmp - CVE-2008-6123

 

#VU32864 Input validation error in Net-snmp - CVE-2008-6123

Published: February 12, 2009 / Updated: July 28, 2020


Vulnerability identifier: #VU32864
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2008-6123
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Net-snmp
Software vendor:
net-snmp.sourceforge.net

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion."


Remediation

Install update from vendor's website.

External links