积极预防 及时发现
快速响应 力保恢复
SNMP事件响应(traps)是代理系统给管理系统发送的消息,它们一般通知管理系统发生了什么事情或提...
发布时间:2002-03-12 信息来源:管理员

CNCVE编号:CNCVE-20020055 CVE编号:CAN-2002-0012 安全级别:高 漏洞中文描述: SNMP事件响应(traps)是代理系统给管理系统发送的消息,它们一般通知管理系统发生了什么事情或提供代理情况的信息。许多厂商的SNMP实现中存在多个安全漏洞。这些漏洞发生在SNMP Trap信息解码和解释的处理上。这些漏洞可能引起拒绝服务攻击而且攻击者可能破坏目标系统。各种受影响产品各自的影响程度各不一致。Microsoft已经确认如果启动了SNMP服务,远程攻击者可以在目标主机上执行任意代码。HP已经确认一个巨大的事件响应(traps)可以让OpenView Network Node Manager崩溃,这可能是缓冲溢出引起的。 漏洞英文描述: SNMP traps are messages sent from agent to manager systems. They typically notify the manager that some event has occurred or otherwise provide information about the status of the agent. Multiple vulnerabilities have been discovered in a number of SNMP implementations. The vulnerabilities are known to exist in the process of decoding and interpreting SNMP trap messages. Among the possible consequences are denial of service and allowing attackers to compromise target systems. These depend on the individual vulnerabilities in each affected product. Microsoft has confirmed that remote attackers may execute arbitrary code on vulnerable hosts if the SNMP service is enabled. HP has confirmed that large traps will cause OpenView Network Node Manager to crash. This may be due to an exploitable buffer overflow condition. Both of these issues will soon be given individual vulnerability records and Bugtraq Ids. 漏洞参考: http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/0100.html ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.4 http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-014.php3 https://www.redhat.com/support/errata/RHSA-2001-16 系统类型:其他 漏洞类型:缓冲区溢出