Mandrake Linux Security Advisory : net-snmp (MDKSA-2006:025)

critical Nessus Plugin ID 20819

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

The fixproc application in Net-SNMP creates temporary files with predictable file names which could allow a malicious local attacker to change the contents of the temporary file by exploiting a race condition, which could possibly lead to the execution of arbitrary code. As well, a local attacker could create symbolic links in the /tmp directory that point to a valid file that would then be overwritten when fixproc is executed (CVE-2005-1740).

A remote Denial of Service vulnerability was also discovered in the SNMP library that could be exploited by a malicious SNMP server to crash the agent, if the agent uses TCP sockets for communication (CVE-2005-2177).

The updated packages have been patched to correct these problems.

Solution

Update the affected packages.

Plugin Details

Severity: Critical

ID: 20819

File Name: mandrake_MDKSA-2006-025.nasl

Version: 1.18

Type: local

Published: 1/29/2006

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:lib64net-snmp5, p-cpe:/a:mandriva:linux:lib64net-snmp5-devel, p-cpe:/a:mandriva:linux:lib64net-snmp5-static-devel, p-cpe:/a:mandriva:linux:libnet-snmp5, p-cpe:/a:mandriva:linux:libnet-snmp5-devel, p-cpe:/a:mandriva:linux:libnet-snmp5-static-devel, p-cpe:/a:mandriva:linux:net-snmp, p-cpe:/a:mandriva:linux:net-snmp-mibs, p-cpe:/a:mandriva:linux:net-snmp-trapd, p-cpe:/a:mandriva:linux:net-snmp-utils, p-cpe:/a:mandriva:linux:perl-netsnmp, cpe:/o:mandrakesoft:mandrake_linux:10.1, x-cpe:/o:mandrakesoft:mandrake_linux:le2005

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Available: true

Exploit Ease: No exploit is required

Patch Publication Date: 1/26/2006

Reference Information

CVE: CVE-2005-1740, CVE-2005-2177

BID: 13715

CWE: 20

MDKSA: 2006:025