[Bug 331410] Re: CVE-2008-6123: not fixed in latest security releases

Marc Deslauriers marc.deslauriers at ubuntu.com
Mon Mar 2 21:54:47 GMT 2009


The CVE-2008-6123 security issue was introduced in the following commit:
http://net-snmp.svn.sourceforge.net/viewvc/net-snmp?view=rev&revision=16654

So, the issue was introduced in 5.2.5, 5.3.2 and 5.4.2.

None of our releases are impacted by this.

dapper: 5.2.1.2-4ubuntu2.3
gutsy: 5.3.1-6ubuntu2.2
hardy: 5.4.1~dfsg-4ubuntu4.2,
intrepid: 5.4.1~dfsg-7.1ubuntu6.1
jaunty: 5.4.1~dfsg-12ubuntu1

Closing as invalid. Feel free to open again if this is incorrect.

** Changed in: net-snmp (Ubuntu Gutsy)
       Status: In Progress => Invalid

** Changed in: net-snmp (Ubuntu Hardy)
       Status: In Progress => Invalid

** Changed in: net-snmp (Ubuntu Dapper)
       Status: New => Invalid

** Changed in: net-snmp (Ubuntu Intrepid)
       Status: In Progress => Invalid

** Changed in: net-snmp (Ubuntu Jaunty)
       Status: In Progress => Invalid

-- 
CVE-2008-6123: not fixed in latest security releases
https://bugs.launchpad.net/bugs/331410
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to net-snmp in ubuntu.



More information about the Ubuntu-server-bugs mailing list