积极预防 及时发现
快速响应 力保恢复
Net-SNMP是一个免费的,开放源码的SNMP实现,以前称为UCD-SNMP。SNMP请求从管理系...
发布时间:2002-03-11 信息来源:管理员

CNCVE编号:CNCVE-20020017 CVE编号: 安全级别:高 漏洞中文描述: Net-SNMP是一个免费的,开放源码的SNMP实现,以前称为UCD-SNMP。SNMP请求从管理系统发往代理,通常用来获取设备的信息或更改其设置。SNMP traps是从代理发送到管理系统的信息,它通常是用于某些事件发生时通知管理系统,并向管理系统提供代理的状态信息。某些低版本的Net-SNMP实现上存在多个缓冲区溢出漏洞,远程攻击者可能借这些漏洞得到运行Net-SNMP服务的主机的管理权限。多种SNMP的实现存在漏洞,这个Net-SNMP的问题是其中的一个。 漏洞英文描述: Net-SNMP is a freely available, open source implementation of the SNMP protocol. It was previously known as UCD-SNMP. SNMP requests are messages sent from manager to agent systems. They typically poll the agent for current performance or configuration information, ask for the next SNMP object in a Management Information Base (MIB), or modify the configuration settings of the agent. SNMP traps are messages sent from agent to manager systems. They typically notify the manager that some event has occurred or otherwise provide information about the status of the agent. Multiple vulnerabilities have been discovered in a number of SNMP implementations. This vulnerability entry is for the Net-SNMP implementation, identifying the "Multiple Vendor SNMP Trap Handling Vulnerabilities" described in BID 4088, and "Multiple Vendor SNMP Request Handling Vulnerabilities" discussed in BID 4089. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0353.html http://www.cert.org/advisories/CA-2002-03.html http://www.caldera.com/support/security/advisories/CSSA-2002-004.0.txt http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-014.php3 h 系统类型:其他 漏洞类型:缓冲区溢出