... e vechi ;P ... a venit pe bugtraq aku vro doua saptamani ;P
On Wed, 13 Feb 2002, Camelia NASTASE wrote: > > > scuzati lipsa traducerii, e prea matinal si mi se pare prea urgenta > chestia ca sa mai stau sa traduc. > > > blonda > -- > Camelia Nastase, [EMAIL PROTECTED] > Network Administrator > Dynamic Network Technologies, Romania > Tel: +40-1-2106863 Fax: +40-1-3122745 > > > ---------- Forwarded message ---------- > Date: Tue, 12 Feb 2002 15:20:28 -0800 (PST) > From: FreeBSD Security Advisories <[EMAIL PROTECTED]> > To: FreeBSD Security Advisories <[EMAIL PROTECTED]> > Subject: FreeBSD Ports Security Advisory FreeBSD-SA-02:11.snmp > > ============================================================================= > FreeBSD-SA-02:11 Security Advisory > FreeBSD, Inc. > > Topic: ucd-snmp/net-snmp remotely exploitable vulnerabilities > > Category: ports > Module: net-snmp > Announced: 2002-02-12 > Credits: OUSPG: Oulu University Secure Programming Group > http://www.ee.oulu.fi/research/ouspg/ > Affects: Ports collection prior to the correction date > Corrected: 2002-01-21 16:54:50 UTC > FreeBSD only: NO > CERT: CA-2002-03 > > I. Background > > The Net-SNMP (previously known as UCD-SNMP) package is a set of Simple > Network Management Protocol tools, including an agent, library, and > applications for generating and handling requests and traps. > > NOTE: The Net-SNMP port directory is ports/net/net-snmp, but the > package name is still ucd-snmp. > > II. Problem Description > > The Net-SNMP port, versions prior to 4.2.3, contains several remotely > exploitable vulnerabilities. The OUSPG has discovered vulnerabilities > in many SNMPv1 implementations through their `PROTOS - Security > Testing of Protocol Implementations' project. The vulnerabilities are > numerous and affect SNMPv1 request and trap handling in both managers > and agents. Please refer to the References section for complete > details. > > The Net-SNMP port is not installed by default, nor is it "part of > FreeBSD" as such: it is part of the FreeBSD ports collection, which > contains over 6000 third-party applications in a ready-to-install > format. The ports collection shipped with FreeBSD 4.5 does not > contains this problem. > > FreeBSD makes no claim about the security of these third-party > applications, although an effort is underway to provide a security > audit of the most security-critical ports. > > III. Impact > > Although no exploits are known to exist at this time, the > vulnerabilities may be exploited by a remote attacker in order to > cause the SNMP agent to execute arbitrary code with superuser > privileges. Malicious agents may respond to requests with specially > constructed replies that cause arbitrary code to be executed by the > client. Knowledge of the SNMP community name is unnecessary for such > exploits to be effective. > > > IV. Workaround > > 1) Deinstall the ucd-snmp port/package if you have it installed. > > V. Solution > > Do one of the following: > > 1) Upgrade your entire ports collection and rebuild the port. > > 2) Deinstall the old package and install a new package dated after the > correction date, obtained from the following directories: > > [i386] > ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/net/ucd-snmp-4.2.3.tgz > > [alpha] > Packages are not automatically generated for the alpha architecture at > this time due to lack of build resources. > > 3) Download a new port skeleton for the net-snmp port from: > > http://www.freebsd.org/ports/ > > and use it to rebuild the port. > > 4) Use the portcheckout utility to automate option (3) above. The > portcheckout port is available in /usr/ports/devel/portcheckout or the > package can be obtained from: > > >ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/Latest/portcheckout.tgz > > NOTE: Many other applications utilize the Net-SNMP libraries. These > applications may also be vulnerable. It is recommended that such > applications be rebuilt after upgrading Net-SNMP. The following > command will display applications installed by the FreeBSD ports > collection that utilize Net-SNMP: > > pkg_info -R ucd-snmp-\* > > VI. Correction details > > The following list contains the revision numbers of each file that was > corrected in the FreeBSD ports collection. > > Path Revision > ------------------------------------------------------------------------- > ports/net/net-snmp/Makefile 1.59 > ports/net/net-snmp/distinfo 1.15 > ports/net/net-snmp/pkg-plist 1.18 > ports/net/net-snmp/files/freebsd4.h (removed) > ports/net/net-snmp/files/patch-aclocal.m4 1.1 > ------------------------------------------------------------------------- > > VII. References > > <URL:http://www.cert.org/advisories/CA-2002-03.html> > <URL:http://www.ee.oulu.fi/research/ouspg/protos/> > <URL:http://www.kb.cert.org/vuls/id/107186> > <URL:http://www.kb.cert.org/vuls/id/854306> > > To Unsubscribe: send mail to [EMAIL PROTECTED] > with "unsubscribe freebsd-security" in the body of the message > ------------ Output from gpg ------------ > gpg: Signature made Wed Feb 13 01:17:35 2002 EET using RSA key ID 73D288A5 > gpg: Can't check signature: public key not found > > > __________________________________________________________ > Send 'unsubscribe rofug' to [EMAIL PROTECTED] to unsubscribe > -- ...peace -;) Jaymzu __________________________________________________________ Send 'unsubscribe rofug' to [EMAIL PROTECTED] to unsubscribe

