{"api_version":"1","generated_at":"2026-07-23T22:21:51+00:00","cve":"CVE-2008-6123","urls":{"html":"https://cve.report/CVE-2008-6123","api":"https://cve.report/api/cve/CVE-2008-6123.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-6123","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-6123"},"summary":{"title":"CVE-2008-6123","description":"The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to \"source/destination IP address confusion.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2009-02-12 16:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-863","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp?view=rev&revision=17367","name":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp?view=rev&revision=17367","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"],"title":"SourceForge.net Repository - [net-snmp] Revision 17367","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10289","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10289","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html","name":"http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2009:011","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1021921","name":"http://www.securitytracker.com/id?1021921","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Net-snmp netsnmp_udp_fmtaddr() Lets Remote Users Bypass Access Controls - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.gentoo.org/show_bug.cgi?id=250429","name":"http://bugs.gentoo.org/show_bug.cgi?id=250429","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"],"title":"Gentoo Bug 250429 - <net-analyzer/net-snmp-5.4.2.1-r1 tcp-wrappers vulnerability allowing 3rd parties to access snmpd (CVE-2008-6123)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/trunk/net-snmp/snmplib/snmpUDPDomain.c?r1=17325&r2=17367&pathrev=17367","name":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/trunk/net-snmp/snmplib/snmpUDPDomain.c?r1=17325&r2=17367&pathrev=17367","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=485211","name":"https://bugzilla.redhat.com/show_bug.cgi?id=485211","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch"],"title":"Bug 485211 – CVE-2008-6123 net-snmp: incorrect application of hosts access restrictions in hosts.{allow,deny}","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/02/12/2","name":"http://www.openwall.com/lists/oss-security/2009/02/12/2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"oss-security - CVE Request -- net-snmp (sensitive host information disclosure)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/34499","name":"http://secunia.com/advisories/34499","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Red Hat update for net-snmp - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/02/12/4","name":"http://www.openwall.com/lists/oss-security/2009/02/12/4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"oss-security - Re: CVE Request -- net-snmp (sensitive host information\n disclosure)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35416","name":"http://secunia.com/advisories/35416","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"SUSE Update for Multiple Packages - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2010:003","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/02/12/7","name":"http://www.openwall.com/lists/oss-security/2009/02/12/7","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"oss-security - Re: CVE Request -- net-snmp (sensitive host\n\tinformation disclosure)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2009-0295.html","name":"http://www.redhat.com/support/errata/RHSA-2009-0295.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35685","name":"http://secunia.com/advisories/35685","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html","name":"http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2009:012","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-6123","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-6123","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"6123","vulnerable":"1","versionEndIncluding":"5.4.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"net-snmp","cpe5":"net-snmp","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"6123","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"opensuse","cpe6":"10.3-11.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"6123","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"opensuse","cpe6":"11.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"6123","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"redhat","cpe5":"enterprise_linux","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"6123","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"suse","cpe5":"linux_enterprise","cpe6":"9-11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T11:20:25.209Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"[oss-security] 20090212 CVE Request -- net-snmp (sensitive host information disclosure)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/2"},{"name":"[oss-security] 20090212 Re: CVE Request -- net-snmp (sensitive host information disclosure)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/7"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=250429"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=485211"},{"name":"[oss-security] Re: 20090212 CVE Request -- net-snmp (sensitive host information disclosure)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/4"},{"name":"SUSE-SR:2009:011","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html"},{"name":"SUSE-SR:2010:003","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html"},{"name":"RHSA-2009:0295","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2009-0295.html"},{"name":"35685","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35685"},{"name":"34499","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34499"},{"name":"SUSE-SR:2009:012","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html"},{"name":"35416","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35416"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp?view=rev&revision=17367"},{"name":"oval:org.mitre.oval:def:10289","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10289"},{"name":"1021921","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1021921"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/trunk/net-snmp/snmplib/snmpUDPDomain.c?r1=17325&r2=17367&pathrev=17367"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-12-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to \"source/destination IP address confusion.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"[oss-security] 20090212 CVE Request -- net-snmp (sensitive host information disclosure)","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/2"},{"name":"[oss-security] 20090212 Re: CVE Request -- net-snmp (sensitive host information disclosure)","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/7"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=250429"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=485211"},{"name":"[oss-security] Re: 20090212 CVE Request -- net-snmp (sensitive host information disclosure)","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/02/12/4"},{"name":"SUSE-SR:2009:011","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html"},{"name":"SUSE-SR:2010:003","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html"},{"name":"RHSA-2009:0295","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2009-0295.html"},{"name":"35685","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35685"},{"name":"34499","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34499"},{"name":"SUSE-SR:2009:012","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html"},{"name":"35416","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35416"},{"tags":["x_refsource_CONFIRM"],"url":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp?view=rev&revision=17367"},{"name":"oval:org.mitre.oval:def:10289","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10289"},{"name":"1021921","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1021921"},{"tags":["x_refsource_MISC"],"url":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/trunk/net-snmp/snmplib/snmpUDPDomain.c?r1=17325&r2=17367&pathrev=17367"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-6123","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to \"source/destination IP address confusion.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"[oss-security] 20090212 CVE Request -- net-snmp (sensitive host information disclosure)","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/02/12/2"},{"name":"[oss-security] 20090212 Re: CVE Request -- net-snmp (sensitive host information disclosure)","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/02/12/7"},{"name":"http://bugs.gentoo.org/show_bug.cgi?id=250429","refsource":"CONFIRM","url":"http://bugs.gentoo.org/show_bug.cgi?id=250429"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=485211","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=485211"},{"name":"[oss-security] Re: 20090212 CVE Request -- net-snmp (sensitive host information disclosure)","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2009/02/12/4"},{"name":"SUSE-SR:2009:011","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html"},{"name":"SUSE-SR:2010:003","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html"},{"name":"RHSA-2009:0295","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2009-0295.html"},{"name":"35685","refsource":"SECUNIA","url":"http://secunia.com/advisories/35685"},{"name":"34499","refsource":"SECUNIA","url":"http://secunia.com/advisories/34499"},{"name":"SUSE-SR:2009:012","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html"},{"name":"35416","refsource":"SECUNIA","url":"http://secunia.com/advisories/35416"},{"name":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp?view=rev&revision=17367","refsource":"CONFIRM","url":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp?view=rev&revision=17367"},{"name":"oval:org.mitre.oval:def:10289","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10289"},{"name":"1021921","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1021921"},{"name":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/trunk/net-snmp/snmplib/snmpUDPDomain.c?r1=17325&r2=17367&pathrev=17367","refsource":"MISC","url":"http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/trunk/net-snmp/snmplib/snmpUDPDomain.c?r1=17325&r2=17367&pathrev=17367"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-6123","datePublished":"2009-02-12T16:00:00.000Z","dateReserved":"2009-02-12T00:00:00.000Z","dateUpdated":"2024-08-07T11:20:25.209Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-02-12 16:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-863","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:net-snmp:net-snmp:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.9","versionEndIncluding":"5.4.2.1","matchCriteriaId":"92CC90A4-8D48-44D2-9F32-A4CAC212E16A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:10.3-11.1:*:*:*:*:*:*:*","matchCriteriaId":"F7018930-D354-4B31-870E-D0E3CE19C8B5"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*","matchCriteriaId":"A01C8B7E-EB19-40EA-B1D2-9AE5EA536C95"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise:9-11:*:*:*:*:*:*:*","matchCriteriaId":"170FDFDE-DADB-4CBF-9AB8-3A01C7BA94AB"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:3.0:*:*:*:*:*:*:*","matchCriteriaId":"40D8DAE0-8E75-435C-9BD6-FAEED2ACB47C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"6123","Ordinal":"1","Title":"CVE-2008-6123","CVE":"CVE-2008-6123","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"6123","Ordinal":"1","NoteData":"The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to \"source/destination IP address confusion.\"","Type":"Description","Title":"CVE-2008-6123"},{"CveYear":"2008","CveId":"6123","Ordinal":"2","NoteData":"2009-02-12","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"6123","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}