CVE-2008-6123

EUVD-2008-6093
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
net-snmpnet-snmp
5.0.9 ≤
𝑥
≤ 5.4.2.1
opensuseopensuse
10.3-11.1
opensuseopensuse
11.2
redhatenterprise_linux
3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
net-snmp
bookworm
5.9.3+dfsg-2
fixed
bullseye
5.9+dfsg-4+deb11u1
fixed
bullseye (security)
5.9+dfsg-4+deb11u1
fixed
etch
no-dsa
lenny
no-dsa
sid
5.9.4+dfsg-1.1
fixed
trixie
5.9.4+dfsg-1.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
net-snmp
dapper
not-affected
gutsy
not-affected
hardy
not-affected
intrepid
not-affected
jaunty
not-affected
karmic
not-affected
lucid
Fixed 5.4.2.1~dfsg0ubuntu1-0ubuntu2.1
released
References