Multiple Ucd-Snmp Vulnerabilities

BID:3218

Info

Multiple Ucd-Snmp Vulnerabilities

Bugtraq ID: 3218
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Jul 17 2001 12:00AM
Updated: Jul 17 2001 12:00AM
Credit: Discovered by Caldera during an audit of net-snmp.
Vulnerable: University of California Davis ucd-snmp 4.2.1
+ SCO eServer 2.3.1
University of California Davis ucd-snmp 4.2
University of California Davis ucd-snmp 4.1.2
University of California Davis ucd-snmp 4.1.1
University of California Davis ucd-snmp 4.1
University of California Davis ucd-snmp 4.0.1
University of California Davis ucd-snmp 4.0
SCO eServer 2.3.1
Redhat ucd-snmp-utils-4.2-12.i386.rpm
+ Redhat Linux 7.1
Redhat ucd-snmp-utils-4.1.2-8.i386.rpm
+ Redhat Linux 7.0
Redhat ucd-snmp-utils-4.1.1-2.i386.rpm
+ Redhat Linux 6.2
Redhat ucd-snmp-devel-4.2-12.i386.rpm
+ Redhat Linux 7.1
Redhat ucd-snmp-devel-4.1.2-8.i386.rpm
+ Redhat Linux 7.0
Redhat ucd-snmp-devel-4.1.1-2.i386.rpm
+ Redhat Linux 6.2
Redhat ucd-snmp-4.2-12.i386.rpm
+ Redhat Linux 7.1
Redhat ucd-snmp-4.1.2-8.i386.rpm
+ Redhat Linux 7.0
Redhat ucd-snmp-4.1.1-2.i386.rpm
+ Redhat Linux 6.2
Redhat Linux 7.1 ia64
Redhat Linux 7.1 i386
Redhat Linux 7.1 alpha
Redhat Linux 7.0 i386
Redhat Linux 7.0 alpha
Redhat Linux 6.2 sparc
Redhat Linux 6.2 i386
Redhat Linux 6.2 alpha
Caldera Volution 1.1
+ Caldera OpenLinux Desktop 2.3
- Mandriva Linux Mandrake 7.2
- Mandriva Linux Mandrake 7.1
- Mandriva Linux Mandrake 7.0
- Redhat Linux 6.1
- Redhat Linux 6.2
+ SCO eDesktop 2.4
- SuSE Linux 7.1
- SuSE Linux 7.0
- SuSE Linux 6.4
- Turbolinux Turbolinux 6.1
- Turbolinux Turbolinux 6.0
Caldera OpenLinux Workstation 3.1.1
Caldera OpenLinux Workstation 3.1
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Server 3.1
Caldera OpenLinux eBuilder 2.3.1
Not Vulnerable:

Discussion

Multiple Ucd-Snmp Vulnerabilities

Ucd-Snmp (project now known as 'Net-Snmp') includes a number of applications and utilities implementing the Simple Network Management Protocol (SNMP).

The programs included with Ucd-Snmp contain many possible vulnerabilities. The SIA Threat Analysis Team is currently researching these issues.

So far, a number of possibly exploitable stack overflows have been identified. There may also be temporary file race condition and format string issues.

As more information is discovered, this alert will be updated. Alerts for individual vulnerabilities may be published.

Some of these vulnerabilities may be remotely exploitable through the snmp daemon and the snmp trap daemon.

Exploit / POC

Multiple Ucd-Snmp Vulnerabilities

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Multiple Ucd-Snmp Vulnerabilities

Solution:
Caldera has released upgraded packages.

---

A set of source code patch files are available that can be applied to Ucd-Snmp 4.2.1, archived in a tarball called 'caldera-ucd-snmp-4.2.1-security-patches.tgz'. They originate from the Caldera eServer 2.3.1 fixes. These patch files also correct many non-exploitable overflow conditions and bugs in program code as well as older security vulnerabilities in Ucd-snmp. These patches have not been tested or verified by Security Focus.


Redhat ucd-snmp-4.2-12.i386.rpm

Redhat ucd-snmp-devel-4.2-12.i386.rpm

Redhat ucd-snmp-4.1.2-8.i386.rpm

Redhat ucd-snmp-utils-4.2-12.i386.rpm

Redhat ucd-snmp-utils-4.1.2-8.i386.rpm

Redhat ucd-snmp-devel-4.1.2-8.i386.rpm

Redhat ucd-snmp-utils-4.1.1-2.i386.rpm

Redhat ucd-snmp-4.1.1-2.i386.rpm

Redhat ucd-snmp-devel-4.1.1-2.i386.rpm

Caldera Volution 1.1

SCO eServer 2.3.1

Caldera OpenLinux eBuilder 2.3.1

Caldera OpenLinux Server 3.1

Caldera OpenLinux Workstation 3.1

Caldera OpenLinux Server 3.1.1

Caldera OpenLinux Workstation 3.1.1

University of California Davis ucd-snmp 4.2.1

Redhat Linux 6.2 alpha

Redhat Linux 6.2 i386

Redhat Linux 6.2 sparc

Redhat Linux 7.0 alpha

Redhat Linux 7.0 i386

Redhat Linux 7.1 alpha

Redhat Linux 7.1 ia64

Redhat Linux 7.1 i386

References

Multiple Ucd-Snmp Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report