Your message dated Thu, 02 Jul 2020 04:03:34 +0000
with message-id <[email protected]>
and subject line Bug#963713: fixed in net-snmp 5.8+dfsg-3
has caused the Debian Bug report #963713,
regarding net-snmp: CVE-2019-20892
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
963713: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=963713
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: net-snmp
Version: 5.8+dfsg-2
Severity: grave
Tags: security upstream
Justification: user security hole
Hi,
The following vulnerability was published for net-snmp.
CVE-2019-20892[0]:
| net-snmp before 5.8.1.pre1 has a double free in
| usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk
| request. NOTE: this affects net-snmp packages shipped to end users by
| multiple Linux distributions, but might not affect an upstream
| release.
See [1] for the CVE heads-up post, and [2] the Launchpad Bug where the
issue originally is tracked from. The issue can be verified with:
| # systemctl stop snmpd.service
| # cat >> /var/lib/snmp/snmpd.conf << __EOF__
| createUser testuser SHA "testpass" AES "testpass"
| __EOF__
| # cat >> /etc/snmp/snmpd.conf << __EOF__
| rwuser testuser
| __EOF__
| # systemctl start snmpd.service
| # snmpbulkget -v3 -Cn1 -Cr1472 -l authPriv -u testuser -a SHA -A testpass -x
AES -X testpass 127.0.0.1 1.3.6.1.2.1.1.5 1.3.6.1.2.1.1.7
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2019-20892
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20892
[1] https://www.openwall.com/lists/oss-security/2020/06/25/4
[2] https://bugs.launchpad.net/ubuntu/+source/net-snmp/+bug/1877027
Please adjust the affected versions in the BTS as needed, I'm not sure
where the issue has been introduced, but possibly does not affect
indeed older suites (please do double check).
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: net-snmp
Source-Version: 5.8+dfsg-3
Done: Craig Small <[email protected]>
We believe that the bug you reported is fixed in the latest version of
net-snmp, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Craig Small <[email protected]> (supplier of updated net-snmp package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 02 Jul 2020 13:38:58 +1000
Source: net-snmp
Architecture: source
Version: 5.8+dfsg-3
Distribution: unstable
Urgency: medium
Maintainer: Net-SNMP Packaging Team <[email protected]>
Changed-By: Craig Small <[email protected]>
Closes: 792832 905668 944336 944953 953044 963713 964054
Changes:
net-snmp (5.8+dfsg-3) unstable; urgency=medium
.
[ Helmut Grohne ]
* Improve cross building: (Closes: #944953)
+ Build-Depends: perl-xs-dev for building a perl extension.
+ cross.patch: Detect mysql using pkg-config.
.
[ Craig Small ]
* Log ipv6 error once Closes: #944336
* Move net-snmp-create-v3-user to snmpd Closes: #953044
* snmpd: Quiet on access errors to mounts Closes: #792832
* snmpd: swinst_apt: Don't use dpkg directories Closes: #905668
* libsnmp: Fix double free crash CVE-2019-20892 Closes: #963713
* Enable TLS and DTLS transports Closes: #964054
Checksums-Sha1:
b4b3d05648df63213e1650bff45508240384140f 2812 net-snmp_5.8+dfsg-3.dsc
5e3e11fe7c94623fce06d7a1fa3932e16c7889e4 69736
net-snmp_5.8+dfsg-3.debian.tar.xz
0b5ac7fb78d43a727128a24da54420a25c9714eb 10018
net-snmp_5.8+dfsg-3_amd64.buildinfo
Checksums-Sha256:
e04045dd533dfbc5f685e704602b7e779bda1d2437c27f3ba6b577a45231da6f 2812
net-snmp_5.8+dfsg-3.dsc
9f37979e06d43e2c75d9fae9773256135ff62cdf8f2e46f128471104d0fc1c29 69736
net-snmp_5.8+dfsg-3.debian.tar.xz
9bba88f5d9819a02e1d8a2553af10573d6bf2a3523b221e61e880d75eb20160d 10018
net-snmp_5.8+dfsg-3_amd64.buildinfo
Files:
83aecdf14d294faba634dddb15aad344 2812 net optional net-snmp_5.8+dfsg-3.dsc
55348703bd383888bd9d14f959a91842 69736 net optional
net-snmp_5.8+dfsg-3.debian.tar.xz
2ea51d6edc8ca7fb8dba6ef3f398aec8 10018 net optional
net-snmp_5.8+dfsg-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAl79WO4ACgkQAiFmwP88
hOPP5BAAkIpQfv1NE+TsVzOEr/ow6baYTHPOMVn4XSAKIy6j6PMoCcILUhiH9kZe
/ZfH8EG6z8XtWzgOmVT2qbr90s3xDpxpDZ0WhMo6JPGDeGe5O0mOW5Y12N5rNYhj
ZrW2jKdV3xlQ1wNo0K6lJMRwYlPd418fuypejLUay8+MVaDY1whZ1Zbd9tDXGGsO
vZoYF4/XUNRBgz4prbui3XW7dNalSiVfjsQWL+UUHYANzgrkeN6OyXJdzkaG0lo0
o4tMLTE4rHhS4z2EzZeR+5f9bq/fMEHzy/Laug3v5kCbue5GFoyIAACoh8OMmgJJ
7uI4y1eT80eEKm9ofWVR/+Qfwt9L36yD6tRvb7gSzQ3bcjKALqPv9zBhNlbMCdKA
Fs2K9Oo3VT3p7iFmwN61P2s7FsZWW6rpJ81FSUpAu5GsqHprlDOGfNM0k32Hy6zv
/iIvleDAM+9mw7F+67/Si0AZMtRu+oyo9CIY7nuQvZlFu+XLCs6ATh7KGrWqvjjG
ILa/JKUGukiNIz5cmhw7W1V5TU0+RpAnjakAL5QiPpTtMq9d3ubM6mscRren+5Yz
E3VfFHOpG6FvphPZ90IqKLnWTfWiRwifWBjgDPCYPcvcqQAFguvq7oCwHqUKyAt6
wa1Z92YWdOZWs8iHFlJdPQfESwfJCyu1IvkBXpLAYAfgT/Wjcss=
=NY3W
-----END PGP SIGNATURE-----
--- End Message ---