SHA256
1
0
forked from pool/net-snmp
Go to file
Marcus Meissner ce2dd41ca5 Accepting request 986781 from home:abergmann:net-snmp:Factory
- update to 5.9.2 (bsc#1201103):
  - security:
    - These two CVEs can be exploited by a user with read-only credentials:
      - CVE-2022-24805 A buffer overflow in the handling of the INDEX of
        NET-SNMP-VACM-MIB can cause an out-of-bounds memory access.
      - CVE-2022-24809 A malformed OID in a GET-NEXT to the nsVacmAccessTable
        can cause a NULL pointer dereference.
    - These CVEs can be exploited by a user with read-write credentials:
      - CVE-2022-24806 Improper Input Validation when SETing malformed
        OIDs in master agent and subagent simultaneously
      - CVE-2022-24807 A malformed OID in a SET request to
        SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable can cause an
        out-of-bounds memory access.
      - CVE-2022-24808 A malformed OID in a SET request to
        NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference
      - CVE-2022-24810 A malformed OID in a SET to the nsVacmAccessTable
        can cause a NULL pointer dereference.
- Refactor two patches to work with version number 5.9.2:
  delete:
  * net-snmp-5.9.1-pie.patch
  * net-snmp-5.9.1-fix-create-v3-user-outfile.patch
  add:
  * net-snmp-5.9.2-pie.patch
  * net-snmp-5.9.2-fix-create-v3-user-outfile.patch

OBS-URL: https://build.opensuse.org/request/show/986781
OBS-URL: https://build.opensuse.org/package/show/network:utilities/net-snmp?expand=0&rev=46
2022-07-06 11:22:09 +00:00
.gitattributes OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/net-snmp?expand=0&rev=1 2007-01-15 23:26:37 +00:00
.gitignore OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/net-snmp?expand=0&rev=1 2007-01-15 23:26:37 +00:00
baselibs.conf Accepting request 927776 from home:abergmann:net-snmp:Factory2 2021-10-27 13:24:30 +00:00
net-snmp-5.9.1-add-lustre-fs-support.patch Accepting request 926819 from home:abergmann:net-snmp:Factory2 2021-10-22 15:22:52 +00:00
net-snmp-5.9.1-fix-Makefile.PL.patch Accepting request 966059 from home:abergmann:net-snmp:Factory 2022-03-31 07:50:07 +00:00
net-snmp-5.9.1-harden_snmpd.service.patch Accepting request 926819 from home:abergmann:net-snmp:Factory2 2021-10-22 15:22:52 +00:00
net-snmp-5.9.1-harden_snmptrapd.service.patch Accepting request 926819 from home:abergmann:net-snmp:Factory2 2021-10-22 15:22:52 +00:00
net-snmp-5.9.1-modern-rpm-api.patch Accepting request 966059 from home:abergmann:net-snmp:Factory 2022-03-31 07:50:07 +00:00
net-snmp-5.9.1-net-snmp-config-headercheck.patch Accepting request 966059 from home:abergmann:net-snmp:Factory 2022-03-31 07:50:07 +00:00
net-snmp-5.9.1-perl-tk-warning.patch Accepting request 966059 from home:abergmann:net-snmp:Factory 2022-03-31 07:50:07 +00:00
net-snmp-5.9.1-snmpstatus-suppress-output.patch Accepting request 966059 from home:abergmann:net-snmp:Factory 2022-03-31 07:50:07 +00:00
net-snmp-5.9.1-socket-path.patch Accepting request 966059 from home:abergmann:net-snmp:Factory 2022-03-31 07:50:07 +00:00
net-snmp-5.9.1-subagent-set-response.patch Accepting request 966059 from home:abergmann:net-snmp:Factory 2022-03-31 07:50:07 +00:00
net-snmp-5.9.1-suse-systemd-service-files.patch Accepting request 926819 from home:abergmann:net-snmp:Factory2 2021-10-22 15:22:52 +00:00
net-snmp-5.9.1-testing-empty-arptable.patch Accepting request 966059 from home:abergmann:net-snmp:Factory 2022-03-31 07:50:07 +00:00
net-snmp-5.9.1-velocity-mib.patch Accepting request 966059 from home:abergmann:net-snmp:Factory 2022-03-31 07:50:07 +00:00
net-snmp-5.9.2-fix-create-v3-user-outfile.patch Accepting request 986781 from home:abergmann:net-snmp:Factory 2022-07-06 11:22:09 +00:00
net-snmp-5.9.2-pie.patch Accepting request 986781 from home:abergmann:net-snmp:Factory 2022-07-06 11:22:09 +00:00
net-snmp-5.9.2.tar.gz Accepting request 986781 from home:abergmann:net-snmp:Factory 2022-07-06 11:22:09 +00:00
net-snmp-5.9.2.tar.gz.asc Accepting request 986781 from home:abergmann:net-snmp:Factory 2022-07-06 11:22:09 +00:00
net-snmp-rpmlintrc OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/net-snmp?expand=0&rev=8 2008-09-08 14:23:32 +00:00
net-snmp-tmpfs.conf Accepting request 855570 from home:suse_weber:branches:network:utilities 2020-12-16 13:20:31 +00:00
net-snmp.changes Accepting request 986781 from home:abergmann:net-snmp:Factory 2022-07-06 11:22:09 +00:00
net-snmp.keyring Accepting request 920181 from home:AndreasStieger:branches:network:utilities 2021-09-21 08:12:33 +00:00
net-snmp.logrotate Accepting request 817756 from home:Xilanaz:branches:network:utilities 2020-07-21 12:16:02 +00:00
net-snmp.spec Accepting request 986781 from home:abergmann:net-snmp:Factory 2022-07-06 11:22:09 +00:00
README.SUSE Accepting request 82014 from net-snmp:factory 2011-09-14 13:00:35 +00:00
snmpd.conf OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/net-snmp?expand=0&rev=1 2007-01-15 23:26:37 +00:00
snmpd.sysconfig Accepting request 569248 from openSUSE:Factory:Staging:O 2018-02-01 14:18:02 +00:00
snmptrapd.sysconfig Accepting request 569248 from openSUSE:Factory:Staging:O 2018-02-01 14:18:02 +00:00
test_installed OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/net-snmp?expand=0&rev=1 2007-01-15 23:26:37 +00:00

An SNMP agent is a powerful and complex software and, as such, may
be affected by flaws and security issues.  We recommend that SNMP
access (161/udp,162/udp) be blocked at your firewall.

There are also some important changes that have been made in this release
of our package:

      o the daemon now sets a PID file in /var/run/

      o logging is now done directly to /var/log/net-snmpd.log instead
        of sending stderr/stdout through syslog.

      o the daemon is now started with the '-r'.  This option prevents
        snmpd from exiting if it doesn't have permission to read something.
        This only occurs if you start snmpd on a high port as a non-root
        root user.

      o If you need to run snmptrapd, we've provided an init script
        in /etc/init.d/snmptrapd, but the service is disabled by default.
        SNMP traps should be avoided whenever possible because they are
        unreliable (you should poll with snmpget instead) and snmptrapd
        has been the source of many of the security problems with SNMP
        so please don't run this unless you are sure of what you are doing.
        To enable the service, run
          chkconfig snmptrapd on
        and create a configuration file named /etc/snmp/snmptrapd.conf.
        Then, start the daemon with
          rcsnmptrapd start
        Logging is done to /var/log/net-snmpd.log.

        For more information see the manpages for snmptrapd and snmptrapd.conf.

      o Master AgentX support is enabled if you have modules in
        /usr/lib/net-snmp/agents. The domain socket is created as
        /var/run/agentx/master.  You can change this to a network
        interface if needed (see snmpd(1)).  The snmpd init script
        automatically detects and starts any sub-agents in placed into
        /var/lib/net-snmp.

More documentation on the net-snmp package can be found in this directory
as well as the project's homepage: http://www.net-snmp.org/