[ubuntu/precise-security] net-snmp 5.4.3~dfsg-2.4ubuntu1.2 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Apr 14 12:23:24 UTC 2014


net-snmp (5.4.3~dfsg-2.4ubuntu1.2) precise-security; urgency=medium

  * SECURITY UPDATE: denial of service via AgentX subagent timeout
    - debian/patches/CVE-2012-6151.patch: track cancelled sessions in
      agent/mibgroup/agentx/{master.c,master_admin.c}, agent/snmp_agent.c,
      include/net-snmp/agent/snmp_agent.h.
    - CVE-2012-6151
  * SECURITY UPDATE: denial of service in perl trap handler
    - debian/patches/CVE-2014-2285.patch: handle empty community string in
      perl/TrapReceiver/TrapReceiver.xs.
    - CVE-2014-2285
  * SECURITY UPDATE: denial of service via multiple-object requests
    - debian/patches/CVE-2014-2310.patch: fix lengths in
      agent/mibgroup/agentx/protocol.c.
    - CVE-2014-2310

Date: 2014-04-08 14:24:34.277141+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/precise/+source/net-snmp/5.4.3~dfsg-2.4ubuntu1.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Precise-changes mailing list