Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Multiple Vendor SNMP Trap Handling Vulnerabilities

Solution:
Cisco has released upgrades to fix this issue. Contact the vendor.

Microsoft has released fixes which addresses this issue.

Fixes for Windows NT 4 Terminal Server English and German editions were re-released due to file problems in the original versions.

Novell will address this issue in NetWare 6 Support Pack 1 and NetWare 5.1 Support Pack 6. Novell has released a patch for versions 4.11 through 6.0.

Multinet and TCPWare users should contact Process Software directly.

AdventNet will release a service pack for all users of their products around February 20, 2002.

Comtek products will be fixed with version 3.5 to be released some time in February 2002.

Lantronix will address this issue in LRS firmware version B1.3/611(020123).

The default installation of HP Secure OS Software for Linux does not include SNMP. Users who have enabled SNMP on HP Secure OS Software for Linux systems are advised to download the RPMs released by Red Hat.

HP Network Node Manager and Emanate Agents are included with ITO/VPO/OVO on Unix, OVO Windows and VPW/OVO Windows. The appropriate HP NNM/Emanate Agents fixes should be installed with these products. The HP OV/SAM Suite version 3.0.1 is prone to trap handling issues when run as an agent. Further details about how the OV/SAM Suite is affected and how to address the issue may be found in the attached advisory (HPSBUX0202-184).

SGI has released advisory 20030405-01-I to address this issue in Brocade firmware.

Fixes are available for a number of systems:


HP JetDirect x.08.00
  • HP X.21.00
    JetDirect firmware version X.21.00 is not vulnerable.JetDirect Product Numbers that can be freely upgraded to X.08.32, X.21.00 or higher firmware:EIO (Peripherals LaserJet 4000, 5000, 8000, etc...)J3110A 10T [G.08.40]J3111A 10T/10B2/LocalTalk [G.08.40]J3112A Token

  • HP X.21.00
    Jetdirect firmware versions previous to X.08.32 are vulnerable, where X is a letter 'A' through 'K'.JetDirect Product Numbers that can be freely upgraded to X.21.00 or higher firmware:EIO (Peripherals Laserjet 4000, 5000, 8000, ..)J3110A 10TJ3111A 10T/10B2/LocalTalkJ3112A Token Ring (discontinued)J3


HP Procurve Switch 8000M
  • HP C.09.13
    Fixed version of firmware for HP Procurve Switch 1600M (J4120A), HP Procurve Switch 2400M (J4120A), HP Procurve Switch 2424M (J4122A), HP Procurve Switch 4000M (J4121A), and HP Procurve Switch 8000M (J4110A).
    http://www.hp.com/rnd/software/switches.htm


Sun Solaris 8
  • Sun 108869-15

  • Sun 108870-15


3Com PS Hub 40

Microsoft Windows NT Enterprise Server 4.0 SP1

IBM AIX 5.1

Microsoft Windows NT Terminal Server 4.0 SP1

Microsoft Windows NT Server 4.0 SP1

Microsoft Windows NT Terminal Server 4.0 SP6

3Com Dual Speed Hub

HP Procurve Switch 2400M
  • HP C.09.13
    Fixed version of firmware for HP Procurve Switch 1600M (J4120A), HP Procurve Switch 2400M (J4120A), HP Procurve Switch 2424M (J4122A), HP Procurve Switch 4000M (J4121A), and HP Procurve Switch 8000M (J4110A).
    http://www.hp.com/rnd/software/switches.htm


Microsoft Windows NT Server 4.0 SP6

Microsoft Windows 2000 Server SP1

Microsoft Windows NT Server 4.0 SP2

Microsoft Windows XP Professional

Microsoft Windows 2000 Server

HP Procurve Switch 4000M
  • HP C.09.13
    Fixed version of firmware for HP Procurve Switch 1600M (J4120A), HP Procurve Switch 2400M (J4120A), HP Procurve Switch 2424M (J4122A), HP Procurve Switch 4000M (J4121A), and HP Procurve Switch 8000M (J4110A).
    http://www.hp.com/rnd/software/switches.htm


Microsoft Windows 2000 Datacenter Server

Microsoft Windows NT Workstation 4.0 SP6a

Microsoft Windows NT Workstation 4.0 SP2

HP Procurve Switch 4108GL

Microsoft Windows NT Workstation 4.0 SP4

Microsoft Windows NT Terminal Server 4.0 SP2

Microsoft Windows 2000 Datacenter Server SP1

3Com PS Hub 50

Microsoft Windows 2000 Professional SP2

3Com Switch 4400

Microsoft Windows 2000 Professional

Microsoft Windows 98

Sun Solaris 7.0
  • Sun 107709-18


HP JetDirect x.20.00
  • HP X.21.00
    JetDirect firmware version X.21.00 is not vulnerable.JetDirect Product Numbers that can be freely upgraded to X.08.32, X.21.00 or higher firmware:EIO (Peripherals LaserJet 4000, 5000, 8000, etc...)J3110A 10T [G.08.40]J3111A 10T/10B2/LocalTalk [G.08.40]J3112A Token


3Com WebCache 1000

Microsoft Windows NT Workstation 4.0

Microsoft Windows NT Server 4.0

HP Procurve Switch 2512

Microsoft Windows NT Server 4.0 SP4

Microsoft Windows NT Enterprise Server 4.0

Microsoft Windows 2000 Server SP2

HP JetDirect x.08.32
  • HP X.21.00
    JetDirect firmware version X.21.00 is not vulnerable.JetDirect Product Numbers that can be freely upgraded to X.08.32, X.21.00 or higher firmware:EIO (Peripherals LaserJet 4000, 5000, 8000, etc...)J3110A 10T [G.08.40]J3111A 10T/10B2/LocalTalk [G.08.40]J3112A Token

  • HP X.21.00
    Jetdirect firmware versions previous to X.08.32 are vulnerable, where X is a letter 'A' through 'K'.JetDirect Product Numbers that can be freely upgraded to X.21.00 or higher firmware:EIO (Peripherals Laserjet 4000, 5000, 8000, ..)J3110A 10TJ3111A 10T/10B2/LocalTalkJ3112A Token Ring (discontinued)J3


Microsoft Windows 2000 Advanced Server SP1

Microsoft Windows NT Terminal Server 4.0

Microsoft Windows 2000 Advanced Server SP2

Microsoft Windows NT Enterprise Server 4.0 SP3

HP HP-UX (VVOS) 11.0 4

HP OpenView Emanate SNMP Agent 14.2 HP-UX 11.X

SNMP Research Mid-Level Manager 15.3
  • SNMP Research Mid-Level Manager 15.3.1.7
    Mid-Level Manager 15.3.1.7 is available directly from SNMP Research.


SNMP Research DR-Web Manager 15.3
  • SNMP Research DR-Web Manager 15.3.1.7
    DR-Web Manager 15.3.1.7 is available directly from SNMP Research.


SGI Brocade 2.6 .0

Sun Enterprise 10000 Server SSP 3.5

HP OpenView Extensible SNMP Agent 4.0

HP OpenView Network Node Manager 4.1 1 Solaris

Novell Netware 4.11

IBM AIX 4.3.2

HP OpenView Network Node Manager 5.0 1 Solaris

Juniper Networks JUNOS 5.0
  • Juniper Networks JUNOS 5.2
    JUNOS 5.2 is available directly from Juniper Networks.


HP OpenView Network Node Manager 5.0 1 HP-UX
  • HP PHSS_26806


HP OpenView Distributed Management 5.0 3

Lotus Domino SNMP Agents 5.0.1 Solaris x86

Lotus Domino SNMP Agents 5.0.1 Solaris SPARC

HP OpenView Network Node Manager 5.0.2 Windows NT 3.51/4.0

Caldera OpenServer 5.0.5

Caldera OpenServer 5.0.6

HP OpenView Distributed Management 6.0

HP OpenView Network Node Manager 6.0 HP-UX 11.X

HP OpenView Network Node Manager 6.0 NT 4.X/Windows 2000

Novell Netware 6.0

HP OpenView Network Node Manager 6.0 Solaris

HP OpenView Network Node Manager 6.2 NT 4.X/Windows 2000

Caldera UnixWare 7.1 .0







 

Privacy Statement
Copyright 2008, SecurityFocus