Net-SNMP: Denial of service A Denial of Service vulnerability has been discovered in Net-SNMP when processing GETBULK requests. net-snmp 2007-11-20 2007-11-20 198346 remote 5.4.1-r1 5.4.1-r1

Net-SNMP is a collection of tools for generating and retrieving SNMP data.

The SNMP agent (snmpd) does not properly handle GETBULK requests with an overly large "max-repetitions" field.

A remote unauthenticated attacker could send a specially crafted SNMP request to the vulnerable application, possibly resulting in a high CPU and memory consumption.

There is no known workaround at this time.

All Net-SNMP users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/net-snmp-5.4.1-r1"
CVE-2007-5846 p-y p-y p-y