CVE-2008-6123
Summary
| CVE | CVE-2008-6123 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-02-12 16:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Net-snmp | Net-snmp | All | All | All | All |
| Operating System | Opensuse | Opensuse | 10.3-11.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 11.2 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 3.0 | All | All | All |
| Operating System | Suse | Linux Enterprise | 9-11 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SourceForge.net Repository - [net-snmp] Revision 17367 | af854a3a-2127-422b-91ae-364da2661108 | net-snmp.svn.sourceforge.net | Product |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:011 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| Net-snmp netsnmp_udp_fmtaddr() Lets Remote Users Bypass Access Controls - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Gentoo Bug 250429 - <net-analyzer/net-snmp-5.4.2.1-r1 tcp-wrappers vulnerability allowing 3rd parties to access snmpd (CVE-2008-6123) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | Exploit, Issue Tracking |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | net-snmp.svn.sourceforge.net | Product |
| Bug 485211 – CVE-2008-6123 net-snmp: incorrect application of hosts access restrictions in hosts.{allow,deny} | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Patch |
| oss-security - CVE Request -- net-snmp (sensitive host information disclosure) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| Red Hat update for net-snmp - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| oss-security - Re: CVE Request -- net-snmp (sensitive host information disclosure) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| SUSE Update for Multiple Packages - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:003 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| oss-security - Re: CVE Request -- net-snmp (sensitive host information disclosure) | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Not Applicable |
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:012 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Mailing List |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.