Vulnerability in net-snmp Affects Access Control Features
CVE-2008-6123

Currently unrated

Key Information:

Vendor

Net-snmp

Status
Vendor
CVE Published:
12 February 2009

What is CVE-2008-6123?

The netsnmp_udp_fmtaddr function in net-snmp versions 5.0.9 to 5.4.2.1, when configured with TCP wrappers for client authorization, fails to properly interpret the hosts.allow rules. This oversight can enable remote attackers to circumvent expected access controls, leading to unauthorized SNMP query execution. The vulnerability is associated with confusion between source and destination IP addresses, posing a significant risk to system integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.