net-snmp-5.5-54.AXS4.1
エラータID: AXSA:2015-441:02
リリース日:
2015/08/20 Thursday - 16:27
題名:
net-snmp-5.5-54.AXS4.1
影響のあるチャネル:
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- net-snmp の snmp_api.c の snmp_pdu_parse 関数は,SNMP PDU のパースに失敗した場合,netsnmp_variable_list アイテムの varBind 変数を削除せず,巧妙に細工されたパケットによって,リモートの攻撃者がサービス拒否 (クラッシュ) を引き起こし,任意のコードを実行する可能性のある脆弱性があります。
一部CVEの翻訳文はJVNからの引用になります。
http://jvndb.jvn.jp/
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2015-5621
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
追加情報:
N/A
ダウンロード:
SRPMS
- net-snmp-5.5-54.AXS4.1.src.rpm
MD5: b5e6caea929462e4d20ced99c661bc34
SHA-256: 8f8afec8614327bb2b02ea9f5b058b0baf5586b2bd13e18d7608b0202c9eb2de
Size: 5.54 MB
Asianux Server 4 for x86
- net-snmp-5.5-54.AXS4.1.i686.rpm
MD5: 04362d95c019deb65a130799edcf692b
SHA-256: d846a0bc6ac0bcabd668816046facffa2f843254c7e9d80ed710da203c7d4ace
Size: 306.58 kB - net-snmp-devel-5.5-54.AXS4.1.i686.rpm
MD5: 4330abd7324f95c4005db7f25c6fa6b8
SHA-256: 13c018286b0523abe508ceeddbc31f4e704ea037bb69092d051e51db8461e8e0
Size: 305.81 kB - net-snmp-libs-5.5-54.AXS4.1.i686.rpm
MD5: 1ccdc2417bc15b3e1a3b90ca04d0918f
SHA-256: 7c1f211466b26b1a85b2ad094d357f375ebc25b6d3498523cdf8cde8c77861cd
Size: 1.51 MB - net-snmp-perl-5.5-54.AXS4.1.i686.rpm
MD5: 811f769509507f30d99255ad5e707e3c
SHA-256: 23866a663409fa7ebc7a30fb2dc766c9e5d33a6ddc5c8aa285d10839fa6dcaf2
Size: 323.92 kB - net-snmp-python-5.5-54.AXS4.1.i686.rpm
MD5: 057a5ab82d06d5180111647246eab792
SHA-256: 2323096d95d55f48a50b9b4e4d1f6ef324502d6e8b8e124ac515583204ec8453
Size: 74.33 kB - net-snmp-utils-5.5-54.AXS4.1.i686.rpm
MD5: e797269b5cd023b7176de2313e98ae47
SHA-256: 31d5685c5d69d338220a4a3fc161567cb2df1db3c58714296f43174112ddbb3b
Size: 172.91 kB
Asianux Server 4 for x86_64
- net-snmp-5.5-54.AXS4.1.x86_64.rpm
MD5: abd230f2f6332d0ae1357501051d89f9
SHA-256: 10de2bf95f24edaa7b11b53a37f79bd98d67032f3f75c4adc2f8d54254ed77e2
Size: 306.78 kB - net-snmp-devel-5.5-54.AXS4.1.x86_64.rpm
MD5: 50834165f19dae502bc08b0605907ffc
SHA-256: 89c41c0c4c246a41a47907f0cf4ecb9578abb840927ce043972edd5380efb124
Size: 305.33 kB - net-snmp-libs-5.5-54.AXS4.1.x86_64.rpm
MD5: f003786d1281d65e7c9a819bf4e5fa27
SHA-256: a117073f820f220124c87f1acd75d45256a8f21805bb7bd6132a582f602e1c82
Size: 1.55 MB - net-snmp-perl-5.5-54.AXS4.1.x86_64.rpm
MD5: 352200aecd3b56c7358af91f57bc2dcf
SHA-256: 38f446fdfad6f859980c092b22d046cd3f785c6459d4ba87606ddad92c16bd39
Size: 323.20 kB - net-snmp-python-5.5-54.AXS4.1.x86_64.rpm
MD5: f19563c036281441306eb8b15d9bdfda
SHA-256: 3129417c7094e044889dc977f378fef7d97f83d45918d25d52ba97c371a81a22
Size: 74.55 kB - net-snmp-utils-5.5-54.AXS4.1.x86_64.rpm
MD5: 0ed70a0b8d94c5b17d0efa68191f88f1
SHA-256: 8744462b2bcf416bab430d88c0eaeef8a75a5d3b837e8f3ae7c170a6ff3e5f52
Size: 174.98 kB - net-snmp-devel-5.5-54.AXS4.1.i686.rpm
MD5: 4330abd7324f95c4005db7f25c6fa6b8
SHA-256: 13c018286b0523abe508ceeddbc31f4e704ea037bb69092d051e51db8461e8e0
Size: 305.81 kB - net-snmp-libs-5.5-54.AXS4.1.i686.rpm
MD5: 1ccdc2417bc15b3e1a3b90ca04d0918f
SHA-256: 7c1f211466b26b1a85b2ad094d357f375ebc25b6d3498523cdf8cde8c77861cd
Size: 1.51 MB