Net-SNMP: Multiple Vulnerabilities — GLSA 202210-29

Multiple vulnerabilities have been discovered in Net-SNMP, the worst of which could result in denial of service.

Affected packages

net-analyzer/net-snmp on all architectures
Affected versions < 5.9.2
Unaffected versions >= 5.9.2

Background

Net-SNMP is a suite of applications used to implement the Simple Network Management Protocol.

Description

Multiple vulnerabilities have been discovered in Net-SNMP. Please review the CVE identifiers referenced below for details.

Impact

Please review the referenced CVE identifiers for details.

Workaround

There is no known workaround at this time.

Resolution

All Net-SNMP users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-analyzer/net-snmp-5.9.2"
 

References

Release date
October 31, 2022

Latest revision
October 31, 2022: 1

Severity
low

Exploitable
remote

Bugzilla entries