• Net-SNMP vulnerability

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Thursday, July 02, 2020 20:10:04
    net-snmp vulnerability

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS

    Summary

    Net-SNMP could be made to crash if it received specially crafted
    input.

    Software Description

    * net-snmp - SNMP (Simple Network Management Protocol) server
    and applications

    Details

    A double-free bug was discovered in snmpd server. An authenticated
    user could potentially cause a DoS by sending a crafted request to
    the server. (CVE-2019-20892)

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    libsnmp-base - 5.8+dfsg-2ubuntu2.1
    libsnmp-perl - 5.8+dfsg-2ubuntu2.1
    libsnmp35 - 5.8+dfsg-2ubuntu2.1
    snmpd - 5.8+dfsg-2ubuntu2.1

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    After a standard system update you need to restart snmpd to make
    all the necessary changes.

    References

    * CVE-2019-20892

    --- Mystic BBS v1.12 A45 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)