• Net-SNMP vulnerabilities

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Monday, August 24, 2020 16:10:01
    net-snmp vulnerabilities

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS
    * Ubuntu 18.04 LTS
    * Ubuntu 16.04 LTS
    * Ubuntu 14.04 ESM
    * Ubuntu 12.04 ESM

    Summary

    Several security issues were fixed in Net-SNMP.

    Software Description

    * net-snmp - SNMP (Simple Network Management Protocol) server
    and applications

    Details

    Tobias Neitzel discovered that Net-SNMP incorrectly handled
    certain symlinks. An attacker could possibly use this issue to
    access sensitive information. (CVE-2020-15861)

    It was discovered that Net-SNMP incorrectly handled certain
    inputs. An attacker could possibly use this issue to execute
    arbitrary code. This issue only affected Ubuntu 14.04 ESM, Ubuntu
    16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
    (CVE-2020-15862)

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    libsnmp-base - 5.8+dfsg-2ubuntu2.3
    libsnmp-perl - 5.8+dfsg-2ubuntu2.3
    libsnmp35 - 5.8+dfsg-2ubuntu2.3
    snmpd - 5.8+dfsg-2ubuntu2.3

    Ubuntu 18.04 LTS
    libsnmp-base - 5.7.3+dfsg-1.8ubuntu3.5
    libsnmp-perl - 5.7.3+dfsg-1.8ubuntu3.5
    libsnmp30 - 5.7.3+dfsg-1.8ubuntu3.5
    snmpd - 5.7.3+dfsg-1.8ubuntu3.5

    Ubuntu 16.04 LTS
    libsnmp-base - 5.7.3+dfsg-1ubuntu4.5
    libsnmp-perl - 5.7.3+dfsg-1ubuntu4.5
    libsnmp30 - 5.7.3+dfsg-1ubuntu4.5
    snmpd - 5.7.3+dfsg-1ubuntu4.5

    Ubuntu 14.04 ESM
    libsnmp-base - 5.7.2~dfsg-8.1ubuntu3.3+esm1
    libsnmp-perl - 5.7.2~dfsg-8.1ubuntu3.3+esm1
    libsnmp30 - 5.7.2~dfsg-8.1ubuntu3.3+esm1
    snmpd - 5.7.2~dfsg-8.1ubuntu3.3+esm1

    Ubuntu 12.04 ESM
    libsnmp-base - 5.4.3~dfsg-2.4ubuntu1.5
    libsnmp-perl - 5.4.3~dfsg-2.4ubuntu1.5
    libsnmp15 - 5.4.3~dfsg-2.4ubuntu1.5
    snmpd - 5.4.3~dfsg-2.4ubuntu1.5

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    After a standard system update you need to restart snmpd to make
    all the necessary changes.

    References

    * CVE-2020-15861
    * CVE-2020-15862

    --- Mystic BBS v1.12 A45 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)