cbcvebase.
CVE-2008-6123
published 2009-02-12

CVE-2008-6123: The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not…

medium5CVSS 3.1
AVNACLAuNCPINAN
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion."

Affected

10 ranges
VendorProductVersion rangeFixed in
debiannet-snmp< net-snmp 5.4.3~dfsg-1 (bookworm)net-snmp 5.4.3~dfsg-1 (bookworm)
net-snmpnet-snmp>= 0 < 5.4.3~dfsg-15.4.3~dfsg-1
net-snmpnet-snmp>= 0 < 5.4.3~dfsg-15.4.3~dfsg-1
net-snmpnet-snmp>= 0 < 5.4.3~dfsg-15.4.3~dfsg-1
net-snmpnet-snmp>= 0 < 5.4.3~dfsg-15.4.3~dfsg-1
net-snmpnet-snmp5.0.9 – 5.4.2.1
opensuseopensuse
opensuseopensuse
redhatenterprise_linux
suselinux_enterprise

CVSS provenance

nvd5.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM