Files
bpfire/config/rootfiles/packages
Adolf Belka 0915078267 netsnmpd: Update to version 5.9.3
- Update from version 5.9.1 to 5.9.3
- Version 5.9.4 exists but it is indicated that SNMP over TLS and/or DTLS is not
   functioning properly with various versions of OpenSSL. However I could not find which
   versions mentioned in the News or Changelog. The problem will be fixed in a future
   version. There are no CVE fixes in 5.9.4, only a relatively few bug fixes so I
   decided to wait for the fixed version in case there are users using TLS with SNMP.
- Update of rootfile
- 6 CVE fixes in 5.9.3
- Changelog
    5.9.3
	    security:
	      - These two CVEs can be exploited by a user with read-only credentials:
	          - CVE-2022-24805 A buffer overflow in the handling of the INDEX of
	            NET-SNMP-VACM-MIB can cause an out-of-bounds memory access.
	          - CVE-2022-24809 A malformed OID in a GET-NEXT to the nsVacmAccessTable
	            can cause a NULL pointer dereference.
	      - These CVEs can be exploited by a user with read-write credentials:
	          - CVE-2022-24806 Improper Input Validation when SETing malformed
	            OIDs in master agent and subagent simultaneously
	          - CVE-2022-24807 A malformed OID in a SET request to
	            SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable can cause an
	            out-of-bounds memory access.
	          - CVE-2022-24808 A malformed OID in a SET request to
	            NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference
	          - CVE-2022-24810 A malformed OID in a SET to the nsVacmAccessTable
	            can cause a NULL pointer dereference.
	      - To avoid these flaws, use strong SNMPv3 credentials and do not share them.
	        If you must use SNMPv1 or SNMPv2c, use a complex community string
	        and enhance the protection by restricting access to a given IP address
		range.
	      - Thanks are due to Yu Zhang of VARAS@IIE and Nanyu Zhong of VARAS@IIE for
	        reporting the following CVEs that have been fixed in this release, and
	        to Arista Networks for providing fixes.
	    misc:
	      - Snmp-create-v3-user: Fix the snmpd.conf path   @datadir@ is
		expanded in ${datarootdir} so datarootdir must be set before
		@datadir@ is used.
	    general: Many bug fixes
    5.9.2
	    skipped due to a last minute library versioning found bug -- use 5.9.3 instead

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-08-15 10:45:48 +00:00
..
2024-07-10 14:28:48 +00:00
2024-07-10 14:28:48 +00:00
2024-07-10 14:28:48 +00:00
2023-04-18 21:16:10 +00:00
2018-11-13 14:28:00 +00:00
2023-12-06 13:40:14 +00:00
2023-04-18 21:20:11 +00:00
2024-05-07 05:51:18 +00:00
2018-12-01 16:13:25 +00:00
2024-02-04 06:55:10 +00:00
2024-07-22 15:21:21 +00:00
2021-02-01 10:45:54 +00:00
2024-02-10 11:52:39 +00:00
2024-03-20 17:49:27 +01:00
2022-07-27 07:09:30 +00:00
2023-11-21 19:01:09 +00:00
2021-02-05 11:24:25 +00:00
2018-11-09 14:29:04 +00:00
2023-04-24 18:42:10 +00:00
2023-07-26 16:08:59 +00:00
2021-09-05 17:46:41 +00:00
2022-02-11 09:17:43 +00:00
2019-04-03 00:33:44 +01:00
2022-11-29 13:44:15 +01:00
2019-04-03 00:26:13 +01:00
2024-08-15 10:45:13 +00:00
2012-08-24 15:44:11 +02:00
2024-08-13 09:14:15 +00:00
2024-08-13 09:14:30 +00:00
2024-08-14 09:08:54 +00:00
2022-02-16 17:11:25 +00:00
2022-09-01 21:16:50 +00:00
2024-03-12 10:15:49 +00:00
2024-08-13 09:14:55 +00:00
2020-12-21 16:35:10 +00:00
2016-04-05 23:47:36 +01:00
2020-09-30 09:58:51 +00:00
2013-06-19 11:49:34 +02:00
2020-06-19 17:14:59 +00:00
2022-04-24 19:02:37 +00:00
2020-04-26 07:31:17 +00:00
2024-08-09 10:38:43 +00:00
2021-04-26 17:10:50 +00:00
2024-07-02 09:07:19 +00:00
2024-02-25 02:03:24 +01:00
2007-09-15 11:36:05 +00:00
2021-06-10 12:21:56 +00:00
2016-06-01 22:22:33 +01:00
2024-03-12 10:15:49 +00:00
2024-01-03 21:19:41 +00:00
2022-12-26 08:46:17 +00:00
2024-01-23 13:53:38 +00:00
2024-01-23 13:53:47 +00:00
2022-05-30 19:45:10 +00:00
2016-06-01 22:25:06 +01:00
2024-01-23 13:53:58 +00:00
2017-04-11 14:23:54 +01:00
2024-04-28 21:04:02 +00:00
2023-02-10 09:27:17 +00:00
2024-01-30 17:49:46 +00:00
2021-03-22 10:43:34 +00:00
2023-11-21 19:31:28 +00:00
2021-04-07 13:15:46 +00:00
2018-06-18 14:12:43 +01:00
2024-05-19 10:02:10 +02:00
2021-03-10 13:58:24 +00:00
2024-08-13 09:15:14 +00:00
2020-09-24 17:36:37 +00:00
2024-08-09 10:41:05 +00:00
2024-08-15 10:45:48 +00:00
2023-05-03 07:50:09 +00:00
2019-03-25 23:44:24 +00:00
2024-08-13 09:15:20 +00:00
2022-08-10 10:44:31 +00:00
2024-06-04 15:07:20 +02:00
2024-08-15 10:45:29 +00:00
2024-03-14 14:09:02 +00:00
2022-09-01 21:16:49 +00:00
2022-09-01 21:16:49 +00:00
2021-05-11 16:44:46 +00:00
2024-06-04 15:06:34 +02:00
2024-02-04 06:53:49 +00:00
2024-02-04 06:54:38 +00:00
2022-01-18 21:26:56 +00:00
2021-03-22 10:43:23 +00:00
2023-05-18 11:24:29 +00:00
2020-08-18 10:10:13 +00:00
2012-11-26 10:56:48 +01:00
2024-08-14 09:11:15 +00:00
2018-11-11 18:55:35 +00:00
2020-08-17 10:10:11 +00:00
2018-11-11 16:21:01 +00:00
2021-09-10 16:57:06 +00:00
2020-04-25 09:03:26 +00:00
2022-02-15 16:56:31 +00:00
2022-09-01 21:16:50 +00:00
2021-03-22 10:39:44 +00:00
2024-07-02 09:14:10 +00:00
2013-06-06 10:58:04 +02:00
2012-09-18 16:33:47 +02:00
2022-08-05 09:12:54 +00:00
2014-10-30 17:52:50 +01:00
2019-02-07 15:15:26 +00:00
2024-07-22 15:21:21 +00:00
2024-02-10 12:00:18 +00:00
2024-02-05 11:05:02 +01:00
2024-02-05 11:06:29 +01:00
2024-02-05 11:07:03 +01:00
2020-02-16 16:26:35 +01:00
2012-11-15 18:24:16 +01:00
2010-07-12 05:32:07 +02:00
2023-06-15 09:39:10 +00:00
2022-02-06 16:46:42 +00:00
2024-03-19 11:14:42 +00:00
2023-09-01 10:30:33 +00:00
2020-04-26 07:35:14 +00:00