Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Multiple Vendor SNMP Request Handling Vulnerabilities

Solution:
Microsoft has released fixes which addresses this issue.

Cisco has released upgrades. Contact the vendor.

Fixes for Windows NT 4 Terminal Server English and German editions were re-released due to file problems in the original versions.

Nokia fixes for affected versions are available for download directly from Nokia.

Novell will address this issue in NetWare 6 Support Pack 1 and NetWare 5.1 Support Pack 6. Novell has made fixes available for version 4.11 through 6.0.

Multinet and TCPWare users should contact Process Software directly.

AdventNet will release a service pack for all users of their products around February 20, 2002.

Comtek products will be fixed with version 3.5 to be released some time in February 2002.

Lantronix will address this issue in LRS firmware version B1.3/611(020123).

The default installation of HP Secure OS Software for Linux does not include SNMP. Users who have enabled SNMP on HP Secure OS Software for Linux systems are advised to download the RPMs released by Red Hat.

HP Network Node Manager and Emanate Agents are included with ITO/VPO/OVO on Unix, OVO Windows and VPW/OVO Windows. The appropriate HP NNM/Emanate Agents fixes should be installed with these products. The HP OV/SAM Suite version 3.0.1 is prone to trap handling issues when run as an agent. Further details about how the OV/SAM Suite is affected and how to address the issue may be found in the attached advisory (HPSBUX0202-184).

SGI has released advisory 20030405-01-I to address this issue in Brocade firmware.

SGI has released advisory 20030703-01-I to address this issue in Emulex 1Gbit FibreChannel Hub firmware.

Fixes are available for a number of systems:


HP JetDirect x.08.00
  • HP X.21.00
    JetDirect firmware version X.21.00 is not vulnerable.JetDirect Product Numbers that can be freely upgraded to X.08.32, X.21.00 or higher firmware:EIO (Peripherals LaserJet 4000, 5000, 8000, etc...)J3110A 10T [G.08.40]J3111A 10T/10B2/LocalTalk [G.08.40]J3112A Token

  • HP X.21.00
    Jetdirect firmware versions previous to X.08.32 are vulnerable, where X is a letter 'A' through 'K'.JetDirect Product Numbers that can be freely upgraded to X.21.00 or higher firmware:EIO (Peripherals Laserjet 4000, 5000, 8000, ..)J3110A 10TJ3111A 10T/10B2/LocalTalkJ3112A Token Ring (discontinued)J3


HP Procurve Switch 8000M
  • HP C.09.13
    Fixed version of firmware for HP Procurve Switch 1600M (J4120A), HP Procurve Switch 2400M (J4120A), HP Procurve Switch 2424M (J4122A), HP Procurve Switch 4000M (J4121A), and HP Procurve Switch 8000M (J4110A).
    http://www.hp.com/rnd/software/switches.htm


3Com PS Hub 40

Microsoft Windows NT Enterprise Server 4.0 SP1

IBM AIX 5.1

Microsoft Windows NT Terminal Server 4.0 SP1

Microsoft Windows NT Server 4.0 SP1

Microsoft Windows NT Terminal Server 4.0 SP6

3Com Dual Speed Hub

HP Procurve Switch 2400M
  • HP C.09.13
    Fixed version of firmware for HP Procurve Switch 1600M (J4120A), HP Procurve Switch 2400M (J4120A), HP Procurve Switch 2424M (J4122A), HP Procurve Switch 4000M (J4121A), and HP Procurve Switch 8000M (J4110A).
    http://www.hp.com/rnd/software/switches.htm


Microsoft Windows NT Server 4.0 SP6

Microsoft Windows 2000 Server SP1

Microsoft Windows NT Server 4.0 SP2

Microsoft Windows XP Professional

Microsoft Windows 2000 Server

HP Procurve Switch 4000M
  • HP C.09.13
    Fixed version of firmware for HP Procurve Switch 1600M (J4120A), HP Procurve Switch 2400M (J4120A), HP Procurve Switch 2424M (J4122A), HP Procurve Switch 4000M (J4121A), and HP Procurve Switch 8000M (J4110A).
    http://www.hp.com/rnd/software/switches.htm


Microsoft Windows 2000 Datacenter Server

Microsoft Windows NT Workstation 4.0 SP6a

Microsoft Windows NT Workstation 4.0 SP2

HP Procurve Switch 4108GL

Microsoft Windows NT Workstation 4.0 SP4

Microsoft Windows NT Terminal Server 4.0 SP2

Microsoft Windows 2000 Datacenter Server SP1

3Com PS Hub 50

Microsoft Windows 2000 Professional SP2

3Com Switch 4400

Microsoft Windows 2000 Professional

Microsoft Windows 98

HP JetDirect x.20.00
  • HP X.21.00
    JetDirect firmware version X.21.00 is not vulnerable.JetDirect Product Numbers that can be freely upgraded to X.08.32, X.21.00 or higher firmware:EIO (Peripherals LaserJet 4000, 5000, 8000, etc...)J3110A 10T [G.08.40]J3111A 10T/10B2/LocalTalk [G.08.40]J3112A Token


3Com WebCache 1000

Microsoft Windows NT Workstation 4.0

Microsoft Windows NT Server 4.0

HP Procurve Switch 2512

Microsoft Windows NT Server 4.0 SP4

Microsoft Windows NT Enterprise Server 4.0

Microsoft Windows 2000 Server SP2

HP HP-UX (VVOS) 11.0 4

SNMP Research Mid-Level Manager 15.3
  • SNMP Research Mid-Level Manager 15.3.1.7
    Mid-Level Manager 15.3.1.7 is available directly from SNMP Research.


SNMP Research DR-Web Manager 15.3
  • SNMP Research DR-Web Manager 15.3.1.7
    DR-Web Manager 15.3.1.7 is available directly from SNMP Research.


Oracle Enterprise Manager 2.0

Sun SunNet Manager Intel 2.3

SGI Brocade 2.6 .0

Sun SunMC 3.0

Sun SunMC 3.0 RR

Sun Enterprise 10000 Server SSP 3.5

HP OpenView Extensible SNMP Agent 4.0

HP OpenView Network Node Manager 4.1 1 Solaris

Novell Netware 4.11

IBM AIX 4.3.2

HP OpenView Network Node Manager 5.0 1 Solaris

Juniper Networks JUNOS 5.0
  • Juniper Networks JUNOS 5.2
    JUNOS 5.2 is available directly from Juniper Networks.


HP OpenView Network Node Manager 5.0 1 HP-UX
  • HP PHSS_26806


HP OpenView Distributed Management 5.0 3

Lotus Domino SNMP Agents 5.0.1 Solaris x86

Lotus Domino SNMP Agents 5.0.1 Solaris SPARC

HP OpenView Network Node Manager 5.0.2 Windows NT 3.51/4.0

Caldera OpenServer 5.0.5

Caldera OpenServer 5.0.6

Juniper Networks JUNOS 5.1
  • Juniper Networks JUNOS 5.2
    JUNOS 5.2 is available directly from Juniper Networks.


HP OpenView Distributed Management 6.0

HP OpenView Network Node Manager 6.0 HP-UX 11.X

HP OpenView Network Node Manager 6.0 NT 4.X/Windows 2000

Novell Netware 6.0

Caldera UnixWare 7.1 .0

Oracle Enterprise Manager 9.0.1







 

Privacy Statement
Copyright 2008, SecurityFocus