New User, Welcome!     Login

tcp/wrappers

[ GLSA 201001-05 ] net-snmp: Authorization bypass

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A remote attacker can bypass the tcp-wrappers client authorization in
net-snmp.

Background
==========


[ MDVSA-2009:060-1 ] nfs-utils

 _______________________________________________________________________

 Problem Description:

 A security vulnerability has been identified and fixed in nfs-utils,
 which caused TCP Wrappers to ignore netgroups and allows remote
 attackers to bypass intended access restrictions (CVE-2008-4552).
 
 The updated packages have been patched to prevent this.

 Update:

[USN-687-1] nfs-utils vulnerability

the necessary changes.

Details follow:

It was discovered that nfs-utils did not properly enforce netgroup
restrictions when using TCP Wrappers. Remote attackers could bypass the
netgroup restrictions enabled by the administrator and possibly gain
access to sensitive information.


Updated packages for Ubuntu 6.06 LTS:

[ MDVSA-2009:056 ] net-snmp

 Problem Description:

 A vulnerability has been identified and corrected in net-snmp:
 
 The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in
 net-snmp 5.0.9 through 5.4.2, when using TCP wrappers for client
 authorization, does not properly parse hosts.allow rules, which
 allows remote attackers to bypass intended access restrictions
 and execute SNMP queries, related to source/destination IP address
 confusion. (CVE-2008-6123)
 

[ GLSA 200903-06 ] nfs-utils: Access restriction bypass

Description
===========

Michele Marcionelli reported that nfs-utils invokes the hosts_ctl()
function with the wrong order of arguments, which causes TCP Wrappers
to ignore netgroups.

Impact
======


[Suspected Spam][USN-946-1] Net-SNMP vulnerability

In general, a standard system update will make all the necessary changes.

Details follow:

The SNMP server did not correctly validate certain UDP clients when using
TCP wrappers.  Under some situations, a remote attacker could bypass
access restrictions and communicate with the SNMP server, potentially
leading to a loss of privacy or a denial of service.


Updated packages for Ubuntu 10.04:

[ MDVSA-2009:056 ] net-snmp

 Problem Description:

 A vulnerability has been identified and corrected in net-snmp:
 
 The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in
 net-snmp 5.0.9 through 5.4.2, when using TCP wrappers for client
 authorization, does not properly parse hosts.allow rules, which
 allows remote attackers to bypass intended access restrictions
 and execute SNMP queries, related to source/destination IP address
 confusion. (CVE-2008-6123)
 

[USN-507-1] tcp-wrappers vulnerability

=========================================================== 
Ubuntu Security Notice USN-507-1            August 30, 2007
tcp-wrappers vulnerability
https://launchpad.net/bugs/135332
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 7.04


VMSA-2010-0004 ESX Service Console and vMA third party updates

    1.0.9-42.el5

    The nfs-utils package provides a daemon for the kernel NFS server
    and related tools.

    It was discovered that nfs-utils did not use tcp_wrappers
    correctly.  Certain hosts access rules defined in "/etc/hosts.allow"
    and "/etc/hosts.deny" may not have been honored, possibly allowing
    remote attackers to bypass intended access restrictions.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!