Bug 815813 (CVE-2012-2141)
Summary: | CVE-2012-2141 net-snmp: Array index error, leading to out-of heap-based buffer read (snmpd crash) | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sergio Freire <sergio-s-freire> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED ERRATA | QA Contact: | |||||
Severity: | medium | Docs Contact: | |||||
Priority: | medium | ||||||
Version: | unspecified | CC: | aladke, dapospis, jlieskov, jsafrane, nmo.marques, rs | ||||
Target Milestone: | --- | Keywords: | Security | ||||
Target Release: | --- | ||||||
Hardware: | Unspecified | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2013-01-08 09:14:56 UTC | Type: | Bug | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 816549, 820099, 820100 | ||||||
Bug Blocks: | 784298, 816605, 816611 | ||||||
Attachments: |
|
Comment 4
Jan Lieskovsky
2012-04-26 10:46:58 UTC
This issue affects the versions of the net-snmp package, as shipped with Red Hat Enterprise Linux 5 and 6. -- This issue affects the versions of the net-snmp package, as shipped with Fedora release of 15 and 16. Please schedule an update. CVE request: [1] http://www.openwall.com/lists/oss-security/2012/04/26/2 Created net-snmp tracking bugs for this issue Affects: fedora-all [bug 816549] Created attachment 580443 [details]
simple fix
Added CVE as per http://www.openwall.com/lists/oss-security/2012/04/26/2 Hi-ho, upstream here. This is in our tracker as https://sourceforge.net/tracker/index.php?func=detail&aid=3526549&group_id=12694&atid=112694, and we've applied the suggested fix in all supported lines (5.4-trunk). This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2012:0876 https://rhn.redhat.com/errata/RHSA-2012-0876.html This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:0124 https://rhn.redhat.com/errata/RHSA-2013-0124.html Statement: (none) |