积极预防 及时发现
快速响应 力保恢复
SNMP请求是管理系统给代理系统发送的消息,它们通常询问代理系统当前性能和配置信息,请求Manage...
发布时间:2002-03-12 信息来源:管理员

CNCVE编号:CNCVE-20020056 CVE编号: 安全级别:高 漏洞中文描述: SNMP请求是管理系统给代理系统发送的消息,它们通常询问代理系统当前性能和配置信息,请求Management Information Base (MIB)的下一个SNMP对象,或者修改代理的配置。许多SNMP的实现被发现了多个漏洞。这些漏洞发生在SNMP信息的解码和解释的处理上。PROTOS小组开发的c06-SNMPv2测试工具已经发现众多厂商的SNMP实现中对SNMP请求的处理中存在大量的安全问题,攻击者可能通过GetRequest、GetNextRequest、SetRequest命令来使远程SNMP服务器崩溃甚至以SNMP服务器运行权限执行任意代码。各种受影响产品各自的影响程度各不一致。 漏洞英文描述: SNMP requests are messages sent from manager to agent systems. They typically poll the agent for current performance or configuration information, ask for the next SNMP object in a Management Information Base (MIB), or modify the configuration settings of the agent. Multiple vulnerabilities have been discovered in a number of SNMP implementations. The vulnerabilities are known to exist in the process of decoding and interpreting SNMP request messages. Among the possible consequences are denial of service and allowing attackers to compromise target systems. These depend on the individual vulnerabilities in each affected product. 漏洞参考: http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/0100.html ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.4 http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-014.php3 https://www.redhat.com/sup 系统类型:其他 漏洞类型:设计错误