Bug#965166: [Pkg-net-snmp-devel] Bug#965166: snmpd privilege escalation

2020-07-20 Thread Bart Van Assche
On 2020-07-19 20:25, Craig Small wrote: > A patch has been applied to the Net-SNMP v5.8 and master branches that > removes the EXTEND MIB from the list with default MIBs. See also commit > c2b96ee74439 ("snmpd: Disable NET-SNMP-EXTEND-MIB support by default"). > > Is the single line re

Bug#965166: [Pkg-net-snmp-devel] Bug#965166: snmpd privilege escalation

2020-07-19 Thread Craig Small
On Sat, 18 Jul 2020 at 12:04, Bart Van Assche wrote: > Net-SNMP version 5.7.3, the version included in Debian, is no longer > maintained upstream. > I just tested it on snmpd v5.8 released around July 2018 and it has this issue too. A patch has been applied to the Net-SNMP v5.8 and master branch

Bug#965166: [Pkg-net-snmp-devel] Bug#965166: snmpd privilege escalation

2020-07-17 Thread Bart Van Assche
Please trim quoted emails when replying. Net-SNMP version 5.7.3, the version included in Debian, is no longer maintained upstream. A patch has been applied to the Net-SNMP v5.8 and master branches that removes the EXTEND MIB from the list with default MIBs. See also commit c2b96ee74439 ("snmpd: D

Bug#965166: [Pkg-net-snmp-devel] Bug#965166: snmpd privilege escalation

2020-07-17 Thread Craig Small
Hi Bart, Thanks for forwarding the report on. Isn't it a generic net-snmp bug? Debian does use this feature of setting the user to not root but wouldn't anyone using the set the user feature have the same issue? Not sure of the best way to fix this. Maybe not being to set the user in /car files