• Net-SNMP regression

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Tuesday, September 01, 2020 12:10:02
    net-snmp regression

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 18.04 LTS
    * Ubuntu 16.04 LTS
    * Ubuntu 14.04 ESM

    Summary

    USN-4471-1 introduced a regression in Net-SNMP.

    Software Description

    * net-snmp - SNMP (Simple Network Management Protocol) server
    and applications

    Details

    USN-4471-1 fixed a vulnerability in Net-SNMP. The updated
    introduced a regression making nsExtendCacheTime not settable.
    This update fixes the problem adding the cacheTime feature flag.

    Original advisory details:

    Tobias Neitzel discovered that Net-SNMP incorrectly handled
    certain symlinks. An attacker could possibly use this issue to
    access sensitive information. (CVE-2020-15861)

    It was discovered that Net-SNMP incorrectly handled certain
    inputs. An attacker could possibly use this issue to execute
    arbitrary code. This issue only affected Ubuntu 14.04 ESM, Ubuntu
    16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
    (CVE-2020-15862)

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 18.04 LTS
    libsnmp-base - 5.7.3+dfsg-1.8ubuntu3.6
    libsnmp-perl - 5.7.3+dfsg-1.8ubuntu3.6
    libsnmp30 - 5.7.3+dfsg-1.8ubuntu3.6
    snmpd - 5.7.3+dfsg-1.8ubuntu3.6

    Ubuntu 16.04 LTS
    libsnmp-base - 5.7.3+dfsg-1ubuntu4.6
    libsnmp-perl - 5.7.3+dfsg-1ubuntu4.6
    libsnmp30 - 5.7.3+dfsg-1ubuntu4.6
    snmpd - 5.7.3+dfsg-1ubuntu4.6

    Ubuntu 14.04 ESM
    libsnmp-base - 5.7.2~dfsg-8.1ubuntu3.3+esm2
    libsnmp-perl - 5.7.2~dfsg-8.1ubuntu3.3+esm2
    libsnmp30 - 5.7.2~dfsg-8.1ubuntu3.3+esm2
    snmpd - 5.7.2~dfsg-8.1ubuntu3.3+esm2

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    After a standard system update you need to restart snmpd to make
    all the necessary changes.

    References

    * USN-4471-1
    * LP: 1892980

    --- Mystic BBS v1.12 A46 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)