-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2313-1 [email protected] https://www.debian.org/lts/security/ Chris Lamb August 04, 2020 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : net-snmp Version : 5.7.3+dfsg-1.7+deb9u3 CVE IDs : CVE-2020-15861 CVE-2020-15862 Debian Bug : #966599 A privilege escalation vulnerability was discovered in Net-SNMP, a set of tools for collecting and organising information about devices on computer networks, due to incorrect symlink handling (CVE-2020-15861). This security update also applies an upstream fix to their previous handling of CVE-2020-15862 as part of DLA-2299-1. For Debian 9 "Stretch", these problems have been fixed in version 5.7.3+dfsg-1.7+deb9u3. We recommend that you upgrade your net-snmp packages. For the detailed security status of net-snmp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/net-snmp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl8pfuMACgkQHpU+J9Qx HlgdOw//ZA3a7gGd2PWuTtUTJIDErCfopBNOg6SbTXO5fIZ51iIIBNxNo49Q5Utt nTrkEjVDsd81QUsYA1k8ZfaDTwrjleLS2jHqWAj1fwwuqmyx5mAbxP+tbUCEKbCi 29zRDjhvkdvzeSh7V5QGHCVRnAeSxodlrrwb4WHXBVFSDtp5b5bH9wfhSV8GkqfI fiAIsDoGdWQf8sIBuSmzNPUmW3YGz3HQ/53OaVfIOOLPXWpFjgzbpZsHTrmXEC/B 39LE22rq4RuxqPGq/8cnpLlSDZRN3pzKXlg8hvxluO00yRW0g0OxbcxRcExqU/TO He4Lp9XHI6VerbyX9e9h8RJwmnNUG5UqiG0OG4E9H9mahto+nLcqUfoPDhtZTxHD XMCQcRCsS+00DlwPupIMN3FhhUF5kUMXFJ6HdtOt2krtpH/m7GX/U+Qt0WjG5pkQ MLyt85OzXt7NR1kSBlIuOFM1gD2bHJQ8xwIR1N0PRgTP6sIjrycONsdxPjkdgawc ZNZXtj4oWILt4dfWVEwRmbQ/bgj+eI5oVk0Bgxdz2eLsa9PUEKYuOpmUcVuZDR1F GbpQlmNVmd+2smZqEkjVhEf1baRI1ygllxS0vOt7gU7seXmq7YX8hvARhSpLvYrW oVPAuBqy30p0BavtIjl/BrffLR1QTuwOAuLX0LLP+4dENfynmIg= =naYB -----END PGP SIGNATURE-----
