SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

multiple SNMP implementations HMAC authenticationspoofing


Arrow  SecurityAlert : 3933
Arrow  CVE : CVE-2008-0960
Arrow  CWE : CWE-287
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : No
Arrow  Exploit Available : No
Arrow  Credit : Andrea Barisani
Arrow  Published : 13.06.2008

Arrow  Affected Software : Net-SNMP <= 5.4.1, <= 5.3.2, <= 5.2.4,
UCD-SNMP,
eCos,
Juniper Session and Resource Control (SRC) C-series 1.0.0, 2.0.0,
NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2,
SNMP Research before 16.2,
multiple Cisco IOS, CatOS, ACE,
Nexus products



Arrow  Advisory Content :  

2008/06/09 #2008-006 multiple SNMP implementations HMAC authentication
spoofing

Description:

Some SNMP implementations include incomplete HMAC authentication code that
allows spoofing of authenticated SNMPv3 packets.

The authentication code reads the length to be checked from sender input,
this allows the sender to supply single byte HMAC code and have a 1 in 256
chance of matching the correct HMAC and authenticating, as only the first
byte will be checked. The sender would need to know a valid username.

Currently Net-SNMP and UCD-SNMP are known to be vulnerable, other SNMP
implementations may also be affected. The eCos project includes code
derived
from UCD-SNMP and is therefore also affected.

Affected version:

Net-SNMP <= 5.4.1, <= 5.3.2, <= 5.2.4
UCD-SNMP, all versions
eCos, all versions

Fixed version:

Net-SNMP >= 5.4.1.1, >= 5.3.2.1, >= 5.2.4.1
UCD-SNMP, N/A
eCos, N/A

Credit: this issue was reported by CERT/CC, it is tracked as VU#878044.

CVE: CVE-2008-0960

Timeline:
2008-06-05: CERT/CC reports VU#878044 to oCERT requesting joint
coordination
2008-06-05: contacted affected vendors
2008-06-06: added eCos to affected packages
2008-06-09: patched net-snmp packages released
2008-06-09: advisory release

References:
http://sourceforge.net/forum/forum.php?forum_id=833770
http://sourceforge.net/tracker/index.php?func=detail&aid=1989089&group_i
d=12694&atid=456380
http://www.kb.cert.org/vuls/id/878044

Links:
http://www.net-snmp.org
http://www.ece.ucdavis.edu/ucd-snmp
http://ecos.sourceware.org

Permalink:
http://www.ocert.org/advisories/ocert-2008-006.html

--
Andrea Barisani | Founder & Project Coordinator
oCERT | Open Source Computer Emergency Response Team

<lcars (at) ocert (dot) org [email concealed]>
http://www.ocert.org
0x864C9B9E 0A76 074A 02CD E989 CE7F AC3F DA47 578E 864C 9B9E
"Pluralitas non est ponenda sine necessitate"



Arrow  References :

http://www.kb.cert.org/vuls/id/MIMG-7ETS87
http://www.kb.cert.org/vuls/id/MIMG-7ETS5Z
http://www.kb.cert.org/vuls/id/CTAR-7FBS8Q
http://www.kb.cert.org/vuls/id/878044
https://bugzilla.redhat.com/show_bug.cgi?id=447974
http://www.securityfocus.com/bid/29623
http://www.securityfocus.com/archive/1/archive/1/493218/100/0/threaded
http://www.openwall.com/lists/oss-security/2008/06/09/1
http://www.ocert.org/advisories/ocert-2008-006.html
http://sourceforge.net/tracker/index.php?func=detail&aid=1989089&group_id=12694&atid=456380
http://sourceforge.net/forum/forum.php?forum_id=833770
http://secunia.com/advisories/30596
http://secunia.com/advisories/30574
http://rhn.redhat.com/errata/RHSA-2008-0528.html




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

» PHP 5.3.0 5.2.11
   posix_mkfifo()
   open_basedir bypass

Copyright © SecurityReason.com. All Rights Reserved.