-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 30 Jul 2020 11:50:04 +0100 Source: net-snmp Binary: snmpd snmptrapd snmp libsnmp-base libsnmp30 libsnmp30-dbg libsnmp-dev libsnmp-perl python-netsnmp tkmib Architecture: source all amd64 Version: 5.7.3+dfsg-1.7+deb9u2 Distribution: stretch-security Urgency: high Maintainer: Net-SNMP Packaging Team <pkg-net-snmp-devel@lists.alioth.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: libsnmp-base - SNMP configuration script, MIBs and documentation libsnmp-dev - SNMP (Simple Network Management Protocol) development files libsnmp-perl - SNMP (Simple Network Management Protocol) Perl5 support libsnmp30 - SNMP (Simple Network Management Protocol) library libsnmp30-dbg - SNMP (Simple Network Management Protocol) library debug python-netsnmp - SNMP (Simple Network Management Protocol) Python support snmp - SNMP (Simple Network Management Protocol) applications snmpd - SNMP (Simple Network Management Protocol) agents snmptrapd - Net-SNMP notification receiver tkmib - SNMP (Simple Network Management Protocol) MIB browser Closes: 965166 Changes: net-snmp (5.7.3+dfsg-1.7+deb9u2) stretch-security; urgency=high . * Disable NET-SNMP-EXTEND-MIB support by default as it was possible to abuse this Management Information Base for privilege escalation attacks. . Upstream notes: . - It is still possible to enable this MIB via the --with-mib-modules configure option. . - Another MIB that provides similar functionality, namely ucd-snmp/extensible, is disabled by default. . - The security risk of ucd-snmp/pass and ucd-snmp/pass_persist is lower since these modules only introduce a security risk if the invoked scripts are exploitable. . (Closes: #965166) Checksums-Sha1: c9606adb50f56c93e0a2c70f0693d4c0060915f1 3161 net-snmp_5.7.3+dfsg-1.7+deb9u2.dsc ebbbc5e9fc5006edd3e62d595366497592d964a2 3371224 net-snmp_5.7.3+dfsg.orig.tar.xz 0e5d3254ab35c743089d46e750f8ce75b651265e 74824 net-snmp_5.7.3+dfsg-1.7+deb9u2.debian.tar.xz 3e9e0a48de9f46060546da5283b11037f1ce70cb 1595190 libsnmp-base_5.7.3+dfsg-1.7+deb9u2_all.deb 5a9b79cde4eafeed87b282855545046da3345962 1091732 libsnmp-dev_5.7.3+dfsg-1.7+deb9u2_amd64.deb bc4a636258fd63a5e7f12f4960c08e373a34c207 311848 libsnmp-perl-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb 06fe728ba666ac1b2e6c23c473854840fb588e5a 1498090 libsnmp-perl_5.7.3+dfsg-1.7+deb9u2_amd64.deb 864d2321d1e18e6aedf430cb3a1146b0cb72d12c 2876700 libsnmp30-dbg_5.7.3+dfsg-1.7+deb9u2_amd64.deb b09257fe1342e1b4ffb0ce0e1d97df25e0501303 2324494 libsnmp30_5.7.3+dfsg-1.7+deb9u2_amd64.deb 53f8cd245c9da1ee19672467d0b37942baf9cd7e 11692 net-snmp_5.7.3+dfsg-1.7+deb9u2_amd64.buildinfo eec76d3f73dad8f80eca23544b36df150402b23a 41678 python-netsnmp-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb 76c8536af86e232a94b2f3f56a0e59b46777fe05 19460 python-netsnmp_5.7.3+dfsg-1.7+deb9u2_amd64.deb 43edc54c87c48447d483d468e3634c572e1902f3 249848 snmp-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb d60451b58ca240bc549e18144e60964dc0a11f2d 153812 snmp_5.7.3+dfsg-1.7+deb9u2_amd64.deb 5eb0a0f3dea68a8c20dafcf4e895be2fe432efdb 19862 snmpd-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb d4466a23e707bd74bd753ee641fab12c4b54aa70 56354 snmpd_5.7.3+dfsg-1.7+deb9u2_amd64.deb a9e8c92d59fba1797e9cf1ae79feadd688cb8706 22424 snmptrapd-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb 08d2d2a911f78a4193290498419afb90c160b4ef 23962 snmptrapd_5.7.3+dfsg-1.7+deb9u2_amd64.deb 6bde14b3d382241ec32f9d83bb6a86adef16d3f3 1471636 tkmib_5.7.3+dfsg-1.7+deb9u2_all.deb Checksums-Sha256: c656e293d885d444f6319d4685c782ce56833b77d0fb17c246b1aa0c9a359791 3161 net-snmp_5.7.3+dfsg-1.7+deb9u2.dsc 073eb05b926a9d23a2eba3270c4e52dd94c0aa27e8b7cf7f1a4e59a4d3da3fb5 3371224 net-snmp_5.7.3+dfsg.orig.tar.xz f5741237c64f40d72afb6df55ca54bffadf54ca79dc7d267bc348a8a84e925bc 74824 net-snmp_5.7.3+dfsg-1.7+deb9u2.debian.tar.xz b50e6f471ba51024e1de8613b6eba9e5d09cc6a0ab4106b7a36e08e2ee080827 1595190 libsnmp-base_5.7.3+dfsg-1.7+deb9u2_all.deb c3e8b3d63ade609f8a278c1257c95132cac0f1da1814814689af7d71a07391a6 1091732 libsnmp-dev_5.7.3+dfsg-1.7+deb9u2_amd64.deb a0a983ccc9ce11e5dc262895866c04c276fed072afbfbda304952d54d08d7183 311848 libsnmp-perl-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb e42db6f3bb823d9dde0a4eccc6dc66f640f89ddd60b88cf3931891c24217ce61 1498090 libsnmp-perl_5.7.3+dfsg-1.7+deb9u2_amd64.deb a40e057169ce91585b2eeff9a760a7ea318daf7af03a270735367ea91eaaa098 2876700 libsnmp30-dbg_5.7.3+dfsg-1.7+deb9u2_amd64.deb b941cb1b8f0be9a726f955e036ee4b7ea8fd138bd573d3192707e97a7dae5ce7 2324494 libsnmp30_5.7.3+dfsg-1.7+deb9u2_amd64.deb 219688028cc03631672c716157f4cad1a7feaad1e42e3cfc0ff274fe60a1905b 11692 net-snmp_5.7.3+dfsg-1.7+deb9u2_amd64.buildinfo 80bb535f919a4662aa273c622ce1057fdff9429e6bb16b37bd5e68df71039e97 41678 python-netsnmp-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb 1fd4526712dcb0f1f52b8cec4074b66d96f184d09558db67055cc6479801e797 19460 python-netsnmp_5.7.3+dfsg-1.7+deb9u2_amd64.deb 44b0557cd47e5da7ffe71c35bfb1ee4333ac983ec1d8f96e64ed921106889616 249848 snmp-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb 5cf82a977e519de3adda5e7ecd9165c75f05c8a136b26d956780a400f48cbd0e 153812 snmp_5.7.3+dfsg-1.7+deb9u2_amd64.deb 006eb51e5fa734d27258c458ad437f3dcdb70789cd46d7b194deb4e88927a85f 19862 snmpd-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb 29363c208484da3aac7fedcbf9e89db5e7de85eeedfd59b613243ca8f8ee62e0 56354 snmpd_5.7.3+dfsg-1.7+deb9u2_amd64.deb a43cd2c8e96821f512666cbff2a0cd52a3ea5a0f83e25453b973abfa9d12f9b2 22424 snmptrapd-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb 9129ab195533702d6516b669200209c1138e93c49ccffd1093113aa715e81749 23962 snmptrapd_5.7.3+dfsg-1.7+deb9u2_amd64.deb 268e73bade1c3dbc0f1cee8f6ee0d7518c3e1c50ba36fd298c00ce0f900d2341 1471636 tkmib_5.7.3+dfsg-1.7+deb9u2_all.deb Files: 87b4792efa18de414e492cede32246a3 3161 net optional net-snmp_5.7.3+dfsg-1.7+deb9u2.dsc 6391ae27eb1ae34ff5530712bb1c4209 3371224 net optional net-snmp_5.7.3+dfsg.orig.tar.xz 3558538a398ded6454e9993de28db91b 74824 net optional net-snmp_5.7.3+dfsg-1.7+deb9u2.debian.tar.xz 0620a9f27c03a09255adc849904e9db6 1595190 libs optional libsnmp-base_5.7.3+dfsg-1.7+deb9u2_all.deb 3e167a9cb5e6b027c92984bcb7861544 1091732 libdevel optional libsnmp-dev_5.7.3+dfsg-1.7+deb9u2_amd64.deb e3d040b7df0b38b3146e1b0c1f6b2b36 311848 debug extra libsnmp-perl-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb 6bbada1b4adce1c767a9b32f886b49a2 1498090 perl optional libsnmp-perl_5.7.3+dfsg-1.7+deb9u2_amd64.deb e3e72d88f2691895b6b85df889175345 2876700 debug extra libsnmp30-dbg_5.7.3+dfsg-1.7+deb9u2_amd64.deb f3748c71972704ec4e7331012a22781f 2324494 libs optional libsnmp30_5.7.3+dfsg-1.7+deb9u2_amd64.deb 5ceb8f61b41b514f286d2903bdeda46a 11692 net optional net-snmp_5.7.3+dfsg-1.7+deb9u2_amd64.buildinfo beed0438539d89d884866502280b8062 41678 debug extra python-netsnmp-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb 73236e1c8d4fba8f522138d338771eb2 19460 python optional python-netsnmp_5.7.3+dfsg-1.7+deb9u2_amd64.deb 9b3fa2341567864cfd0618ad85c395f2 249848 debug extra snmp-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb 3046587c7b28ee546cfb46d41c0d16be 153812 net optional snmp_5.7.3+dfsg-1.7+deb9u2_amd64.deb 373470a59ceafe580314325a54f62a1c 19862 debug extra snmpd-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb b2894991e0ab52e60b48385a05a895a3 56354 net optional snmpd_5.7.3+dfsg-1.7+deb9u2_amd64.deb 7118a1aea5de8d1f6ff811c9488ef5db 22424 debug extra snmptrapd-dbgsym_5.7.3+dfsg-1.7+deb9u2_amd64.deb 2cb1cf0a8b1acb5667e02fda1982c203 23962 net optional snmptrapd_5.7.3+dfsg-1.7+deb9u2_amd64.deb 30c0bab422666c456fc53d215a718cd4 1471636 net optional tkmib_5.7.3+dfsg-1.7+deb9u2_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl8ip54ACgkQHpU+J9Qx HlgHYhAAg96xAdFUKE0GTBkxCuyeXaj6Jo+wiv3wmuvJ+g0DuapwqoNhT78SpY+b eOxRh+BwTshh4PIaLtlBBMCkW+OLglj4DuVCuX6O+3d44yYgCM9rMffcEajtNNz9 R3xUhPAn0CTQ7gHKrdqYP9e5tV4ASPdRPt/WXhB1Of9kjU9EkXcFc9yVS2XX7/8N Gkr1bDoWWhFrZCRBHF3VCI/GHE2YfiMhYohlCDz27QVD88vwxIVkODl7zYzv8dak 0EruB2xbAPdp9p0KI6+y0ZD2jEbYVXxuIjY+AMhk8iFMt4NdCT5KVr69/Y8/RsrC fs67BdfNkoGY8xl6N8VAKYKJjC208nJ+jFjE0fE2P2rXO+rDgKeaiTZxkemmm/Iw Um+XTXBGSGvaO65ggANFLBfJepsA0kqULur88MY53oS1OLxZdh5AJ3tqJH/Seep/ e6gNbBho0hRX/SjnnjuWKFU1D7BSqRARKQqng3dzxgcgExk3wGs+ffY9i60XBVsA 2g/9zQNHl/hjHbejk3nFpvw+sD8BRe1TiqSHDqmDJTrYkmb0BGCxzSCTQJS7jT64 hUm5xPyq92E7fmC7w1off5szYL/QeXTFZe8YfsmBiIA5pYon6RbHQ59EKTtz+pqd O6hSBbUJN3ORYJP1OAqdqObB97+Hc1XbdWVx3tO7A2fEUV2kDw4= =T8+I -----END PGP SIGNATURE-----