|
|
|
Vulnerability Note VU#107186
Multiple vulnerabilities in SNMPv1 trap handling
OverviewMultiple vendor SNMPv1 Trap handling implementations contain vulnerabilities that may allow unauthorized privileged access, denial-of-service conditions, or unstable behavior . If your site uses SNMP in any capacity, the CERT/CC encourages you to read the information provided below.
I. DescriptionThe Oulu University Secure Programming Group (OUSPG) has reported numerous vulnerabilities in multiple vendor SNMPv1 implementations. By applying the PROTOS c06-SNMPv1 test suite to a variety of popular SNMPv1-enabled products, the OUSPG revealed a number of vulnerabilities across a wide range of products. This vulnerability note focuses on vulnerabilities occurring in code responsible for SNMPv1 trap handling.
SNMPv1 supports five different types of messages: GetRequest, SetRequest, GetNextRequest, GetResponse, and Trap. A single SNMP message is referred to as a Protocol Data Unit (PDU). These messages are described using Abstract Syntax Notation One (ASN.1) and translated into binary format using Basic Encoding Rules (BER). SNMP trap messages are sent from agents to managers. Trap messages are unsolicited (the manager does not issue a request message) and may indicate a warning or error condition or otherwise notify the manager about the agent's state. SNMP managers should reliably decode trap messages and process the resulting application data. OUSPG performed two sets of tests of SNMP trap message handling: one test focused on ASN.1 decoding, the second looked for exceptions in the processing of the decoded data.
The results yielded multiple vulnerabilities in both the ASN.1 decoding and the subsequent processing of SNMP trap messages by many different SNMP managers. Vulnerabilities include denial-of-service conditions, format string vulnerabilities, and buffer overflows. Some vulnerabilities do not require the request message to use the correct SNMP community string.
Additional Background Information on the OUSPG
OUSPG is a academic research group located at Oulu University in Finland. The purpose of this research group is to test software for vulnerabilities.
History has shown that the techniques used by the OUSPG have discovered a large number of previously undetected problems in the products and protocols they have tested. In 2001, the OUSPG produced a comprehensive test suite for evaluating implementations of the Lightweight Directory Access Protocol (LDAP). This test suite was developed with the strategy of stressing protocol implementations in unsupported and unexpected ways, and it was very effective in uncovering a wide variety of vulnerabilities across several products. This approach can reveal vulnerabilities that would not manifest themselves under normal operating conditions.
After completing its work on LDAP, OUSPG moved its focus to SNMPv1. As with LDAP, they designed a custom test suite, began testing a selection of products, and found a number of vulnerabilities. Because OUSPG's work on LDAP was similar in procedure to its current work on SNMP, you may wish to review the LDAP Test Suite and CERT Advisory CA-2001-18, which outlined results of application of the test suite.
In order to test the security of protocols like SNMPv1, the PROTOS project presents a server with a wide variety of sample packets containing unexpected values or illegally formatted data. As a member of the PROTOS project consortium, the OUSPG used the PROTOS c06-snmpv1 test suite to study several implementations of the SNMPv1 protocol. Results of the test suites run against SNMP indicate that there are many different vulnerabilities on many different implementations of SNMP.
Background Information on the Simple Network Management Protocol
The Simple Network Management Protocol (SNMP) is the most popular protocol in use to manage networked devices. SNMP was designed in the late 80's to facilitate the exchange of management information between networked devices, operating at the application layer of the ISO/OSI model. The SNMP protocol enables network and system administrators to remotely monitor and configure devices on the network (devices such as switches and routers). Software and firmware products designed for networks often make use of the SNMP protocol. SNMP runs on a multitude of devices and operating systems, including, but not limited to,
Core Network Devices (Routers, Switches, Hubs, Bridges, and Wireless Network Access Points)
Consumer Broadband Network Devices (Cable Modems and DSL Modems)
Consumer Electronic Devices (Cameras and Image Scanners)
Networked Office Equipment (Printers, Copiers, and FAX Machines)
Network and Systems Management/Diagnostic Frameworks (Network Sniffers and Network Analyzers)
Networked Medical Equipment (Imaging Units and Oscilloscopes)
Manufacturing and Processing Equipment
The SNMPv1 protocol is formally defined in RFC1157. Quoting from that RFC:
Implicit in the SNMP architectural model is a collection of network management stations and network elements. Network management stations execute management applications which monitor and control network elements. Network elements are devices such as hosts, gateways, terminal servers, and the like, which have management agents responsible for performing the network management functions requested by the network management stations. The Simple Network Management Protocol (SNMP) is used to communicate management information between the network management stations and the agents in the network elements.
Additionally, SNMP is discussed in a number of other RFC documents:
RFC 3000 Internet Official Protocol Standards
RFC 1212 Concise MIB Definitions
RFC 1213 Management Information Base for Network Management of TCP/IP-based Internets: MIB-II
RFC 1215 A Convention for Defining Traps for use with the SNMP
RFC 1270 SNMP Communications Services
RFC 2570 Introduction to Version 3 of the Internet-standard Network Management Framework
RFC 2571 An Architecture for Describing SNMP Management Frameworks
RFC 2572 Message Processing and Dispatching for the Simple Network Management Protocol (SNMP)
RFC 2573 SNMP Applications
RFC 2574 User-based Security Model (USM) for version 3 of the Simple Network Management Protocol (SNMPv3)
RFC 2575 View-based Access Control Model (VACM) for the Simple Network Management Protocol (SNMP)
RFC 2576 Coexistence between Version 1, Version 2, and Version 3 of the Internet-standard Network Management Framework
II. ImpactThese vulnerabilities may cause denial-of-service conditions, service interruptions, and in some cases may allow an attacker to gain access to the affected device. Specific impacts will vary from product to product.
III. SolutionNote that many of the mitigation steps recommended below may have significant impact on your everyday network operations and/or network architecture. Care should therefore be taken to ensure that any changes made based on the following recommendations will not negatively impact your ongoing network operations capability.
Contact your vendor for patches.
Please see the Solution section of CA-2002-03 for additional countermeasures.
Systems Affected
| Vendor | Status | Date Updated |
| 2Wire | Unknown | 10-Jan-2002 |
| 3Com | Vulnerable | 20-Feb-2002 |
| Adaptec Inc. | Unknown | 10-Jan-2002 |
| ADC | Unknown | 10-Jan-2002 |
| ADTRAN Inc. | Vulnerable | 21-Feb-2002 |
| ADVA AG Optical Networking | Not Vulnerable | 21-Aug-2002 |
| Advantech | Unknown | 14-Jan-2002 |
| AdventNet | Vulnerable | 7-Nov-2007 |
| Agere Systems | Unknown | 14-Jan-2002 |
| Agilent Technologies | Unknown | 9-Jan-2002 |
| AIRCONNECT | Unknown | 14-Jan-2002 |
| Alcatel | Unknown | 20-Feb-2002 |
| Alidian Networks | Unknown | 14-Jan-2002 |
| Allied Telesyn International | Not Vulnerable | 18-Aug-2003 |
| Alpha Technologies | Unknown | 14-Jan-2002 |
| Alvarion Ltd. | Not Vulnerable | 18-Mar-2002 |
| AMD | Unknown | 11-Jan-2002 |
| American Power Conversion Corporation | Vulnerable | 9-Apr-2002 |
| Amnis Systems | Unknown | 14-Jan-2002 |
| Analog Devices Inc. | Unknown | 11-Jan-2002 |
| Ando Corporation | Unknown | 14-Jan-2002 |
| Apple Computer, Inc. | Not Vulnerable | 12-Mar-2002 |
| Aprisma | Vulnerable | 6-Mar-2002 |
| ARINC Incorporated | Unknown | 14-Jan-2002 |
| Asante Technologies Inc. | Not Vulnerable | 5-Mar-2002 |
| Askey Computer Corporation | Unknown | 14-Jan-2002 |
| Astracon | Not Vulnerable | 15-Aug-2002 |
| Atheros Communications | Unknown | 10-Jan-2002 |
| Atos Origin | Unknown | 9-Jan-2002 |
| Avaya | Vulnerable | 7-Mar-2002 |
| AVET Information and Network Security | Not Vulnerable | 5-Apr-2002 |
| Avici Systems Inc. | Not Vulnerable | 21-Feb-2002 |
| Aware | Unknown | 21-Jan-2002 |
| Aztech Systems Ltd | Unknown | 10-Jan-2002 |
| BEA Systems Inc. | Vulnerable | 19-Jun-2002 |
| Berkeley Software Design, Inc. | Unknown | 19-Dec-2001 |
| BinTec Communications AG | Not Vulnerable | 11-Jun-2002 |
| BMC Software | Vulnerable | 11-Jun-2002 |
| Broadcom Corporation | Unknown | 11-Jan-2002 |
| Brocade Communications Systems Inc. | Unknown | 14-Jan-2002 |
| C-SPEC Corporation | Unknown | 14-Jan-2002 |
| CacheFlow Inc. | Vulnerable | 5-Feb-2002 |
| CalSoft | Unknown | 14-Jan-2002 |
| Cambridge Broadband Limited | Not Vulnerable | 25-Feb-2002 |
| Canoga Perkins Corporation | Not Vulnerable | 12-Apr-2002 |
| Canon U.S.A. Inc. | Unknown | 14-Jan-2002 |
| Carrier Access | Vulnerable | 7-Mar-2002 |
| Cayman Systems Inc. | Unknown | 11-Jan-2002 |
| Charles Industries Ltd | Unknown | 14-Jan-2002 |
| Check Point | Not Vulnerable | 21-Feb-2002 |
| CipherTrust INC | Not Vulnerable | 28-Feb-2002 |
| Cisco Systems, Inc. | Vulnerable | 13-Feb-2002 |
| Clarent Corporation | Unknown | 21-Jan-2002 |
| CNT | Vulnerable | 8-Apr-2002 |
| Compaq Computer Corporation | Vulnerable | 10-Apr-2002 |
| Computer Associates | Vulnerable | 12-Feb-2002 |
| COMTEK Services Inc | Vulnerable | 22-Mar-2002 |
| Comtest | Unknown | 14-Jan-2002 |
| Comtrend Corporation | Unknown | 10-Jan-2002 |
| Concord Communications | Vulnerable | 19-Mar-2002 |
| Conexant Systems Inc. | Unknown | 14-Jan-2002 |
| Controlware GmbH | Not Vulnerable | 20-Mar-2002 |
| Convedia Corporation | Unknown | 10-Jan-2002 |
| Convergent Networks | Unknown | 14-Jan-2002 |
| Copper Mountain Networks Inc. | Unknown | 10-Jan-2002 |
| Coresma | Unknown | 10-Jan-2002 |
| Corsaire Limited | Not Vulnerable | 25-Feb-2002 |
| CoSine Communications | Unknown | 10-Jan-2002 |
| Covalent | Not Vulnerable | 12-Feb-2002 |
| Cray Inc. | Unknown | 5-Apr-2002 |
| Critical Path | Unknown | 14-Jan-2002 |
| Crossroads Systems Inc | Unknown | 10-Jan-2002 |
| CSCare Inc. | Vulnerable | 6-Mar-2002 |
| Cyclades Corporation | Unknown | 18-Jan-2002 |
| D-Link Systems | Not Vulnerable | 28-Feb-2002 |
| Dart Communications | Vulnerable | 27-Feb-2002 |
| Dartware LLC | Not Vulnerable | 5-Mar-2002 |
| Data Connection | Unknown | 10-Jan-2002 |
| Data General | Unknown | 19-Dec-2001 |
| DATAX | Unknown | 14-Jan-2002 |
| Dell | Vulnerable | 19-Apr-2002 |
| Digital Networks | Vulnerable | 25-Jul-2002 |
| DMH Software | Not Vulnerable | 28-Apr-2002 |
| DNE Technologies Inc. | Unknown | 14-Jan-2002 |
| Dynarc | Unknown | 14-Jan-2002 |
| e-Security Inc. | Vulnerable | 19-Mar-2002 |
| Efficient Networks Inc | Not Vulnerable | 4-Mar-2002 |
| EMC Corporation | Unknown | 14-Jan-2002 |
| Emulex | Unknown | 14-Jan-2002 |
| Enterasys Networks | Unknown | 13-Feb-2002 |
| Entrada Networks | Vulnerable | 22-Apr-2002 |
| Equinox Systems | Vulnerable | 19-Mar-2002 |
| Ericsson | Unknown | 9-Jan-2002 |
| Evidian Inc. | Unknown | 5-Apr-2002 |
| Extreme Networks | Unknown | 10-Jan-2002 |
| F5 Networks, Inc. | Vulnerable | 15-Mar-2002 |
| Fluke Corporation | Vulnerable | 26-Apr-2002 |
| Foundry Networks Inc. | Not Vulnerable | 18-Feb-2002 |
| FreeBSD, Inc. | Vulnerable | 13-Feb-2002 |
| Fujitsu | Unknown | 19-Dec-2001 |
| Future Communications Software | Not Vulnerable | 5-Nov-2002 |
| GE Industrial Systems | Unknown | 15-Jan-2002 |
| General DataComm | Vulnerable | 21-Feb-2002 |
| Guardian Digital Inc. | Not Vulnerable | 3-Jan-2002 |
| Halcyon Monitoring Solutions | Unknown | 11-Jan-2002 |
| Haliplex Pty Ltd | Unknown | 14-Jan-2002 |
| Hewlett-Packard Company | Vulnerable | 1-Apr-2002 |
| Hirschmann Electronics GmbH & Co | Vulnerable | 8-Feb-2002 |
| Hitachi | Unknown | 14-Jan-2002 |
| Hitachi | Vulnerable | 24-May-2005 |
| Honeywell | Unknown | 23-Jan-2002 |
| Huawei Technologies | Unknown | 14-Jan-2002 |
| IBM-zSeries | Unknown | 7-Jan-2002 |
| IBM Corporation | Vulnerable | 26-Feb-2002 |
| IMC Networks | Unknown | 14-Jan-2002 |
| Industrial Networking Solutions | Unknown | 10-Jan-2002 |
| InfoVista | Vulnerable | 22-Mar-2002 |
| Inktomi Corporation | Vulnerable | 21-Feb-2002 |
| Innerdive Solutions LLC | Vulnerable | 11-Feb-2002 |
| INRANGE Technologies | Unknown | 26-Feb-2002 |
| Intel | Unknown | 4-Jan-2002 |
| Interniche Technologies | Not Vulnerable | 22-Sep-2003 |
| Interphase Corporation | Unknown | 5-Feb-2002 |
| Intrusion Inc. | Unknown | 15-Jan-2002 |
| Invensys plc | Unknown | 10-Jan-2002 |
| IP Infusion | Unknown | 10-Jan-2002 |
| IPlanet | Vulnerable | 28-Aug-2002 |
| Ipswitch Inc. | Vulnerable | 6-Mar-2002 |
| Ishoni Networks | Unknown | 14-Jan-2002 |
| ITouch Communications | Vulnerable | 6-Mar-2002 |
| Ixia | Unknown | 10-Jan-2002 |
| Juniper Networks, Inc. | Vulnerable | 12-Feb-2002 |
| KarlNet Inc. | Vulnerable | 25-Mar-2002 |
| Kentrox LLC | Unknown | 25-Mar-2002 |
| Komatsu Ltd. | Unknown | 14-Jan-2002 |
| Lachman | Unknown | 7-Jan-2002 |
| Lantronix | Vulnerable | 30-Jan-2002 |
| Larscom Incorporated | Vulnerable | 6-Mar-2002 |
| Legato Systems Inc. | Unknown | 11-Jan-2002 |
| Lexmark International Inc. | Not Vulnerable | 20-Feb-2002 |
| Liebert | Unknown | 11-Jan-2002 |
| Linksys | Unknown | 9-Jan-2002 |
| LOGEC Systems Inc. | Not Vulnerable | 12-Feb-2002 |
| LogiSoft AR | Unknown | 10-Jan-2002 |
| Lotus Software | Vulnerable | 11-Feb-2002 |
| Lucent Technologies | Vulnerable | 21-Feb-2002 |
| Mandriva, Inc. | Vulnerable | 5-Mar-2002 |
| Marconi | Vulnerable | 14-Jan-2002 |
| Marvell | Unknown | 14-Jan-2002 |
| Memotec Communications | Unknown | 11-Jan-2002 |
| Mercury Interactive Corporation | Vulnerable | 23-Sep-2002 |
| MetaSwitch | Unknown | 14-Jan-2002 |
| Metrobility Optical Systems | Vulnerable | 14-May-2003 |
| MG-SOFT Corporation | Vulnerable | 14-Feb-2002 |
| Micromuse | Vulnerable | 15-Feb-2002 |
| Microsoft Corporation | Vulnerable | 13-Feb-2002 |
| Mistral Software Inc. | Unknown | 14-Jan-2002 |
| Modlink Networks | Not Vulnerable | 25-Mar-2002 |
| Monfox LLC | Vulnerable | 4-Mar-2002 |
| Motorola | Unknown | 11-Jan-2002 |
| Multinet | Vulnerable | 19-Dec-2001 |
| Muonics | Not Vulnerable | 11-Jun-2003 |
| M/A-COM | Unknown | 14-Jan-2002 |
| Nbase-Xyplex | Vulnerable | 6-Mar-2002 |
| nCipher Corp. | Not Vulnerable | 1-Mar-2002 |
| NCR | Unknown | 14-Jan-2002 |
| NEC Corporation | Vulnerable | 28-Mar-2002 |
| NET-SNMP | Vulnerable | 16-Feb-2002 |
| NETAPHOR SOFTWARE INC | Unknown | 12-Feb-2002 |
| NetBSD | Unknown | 19-Dec-2001 |
| NETGEAR | Unknown | 10-Jan-2002 |
| Netopia | Unknown | 7-Jan-2002 |
| NetPlane Systems | Unknown | 10-Jan-2002 |
| Netscape Communications Corporation | Vulnerable | 12-Feb-2002 |
| NetScout Systems Inc. | Vulnerable | 26-Mar-2002 |
| NetScreen | Not Vulnerable | 21-Feb-2002 |
| NetSilicon Inc. | Vulnerable | 6-Mar-2002 |
| Network Appliance | Vulnerable | 7-Mar-2002 |
| Network Associates | Not Vulnerable | 25-Jan-2002 |
| Network Computing Technologies | Unknown | 10-Jan-2002 |
| NETWORK HARMONi Inc. | Vulnerable | 20-Mar-2002 |
| net.com | Vulnerable | 7-Mar-2002 |
| NexGen Software | Unknown | 14-Jan-2002 |
| Nishan Systems | Unknown | 10-Jan-2002 |
| Nokia | Not Vulnerable | 3-Jan-2002 |
| Nortel Networks, Inc. | Vulnerable | 22-Feb-2002 |
| Novell, Inc. | Vulnerable | 4-Mar-2002 |
| NuDesign Team Inc. | Vulnerable | 27-Jul-2004 |
| OLE Communications Inc. | Unknown | 14-Jan-2002 |
| Omnitronix | Unknown | 25-Jan-2002 |
| OpenBSD | Not Vulnerable | 8-Feb-2002 |
| Openwave Systems Inc. | Vulnerable | 21-Feb-2002 |
| Optical Access | Vulnerable | 26-Feb-2002 |
| Oracle Corporation | Vulnerable | 7-Mar-2002 |
| Outback Resource Group Inc. | Vulnerable | 24-Apr-2002 |
| Paion | Unknown | 14-Jan-2002 |
| Paradyne Networks Inc. | Unknown | 5-Mar-2002 |
| Perle Systems Ltd | Vulnerable | 26-Feb-2002 |
| Pluris | Unknown | 10-Jan-2002 |
| Polycom | Unknown | 14-Jan-2002 |
| Portmasters | Unknown | 29-Jan-2002 |
| Powerware Corporation | Vulnerable | 7-Mar-2002 |
| Precise Software Technologies Inc. | Unknown | 11-Jan-2002 |
| Prism Communications | Unknown | 10-Jan-2002 |
| Pulsecom | Unknown | 14-Jan-2002 |
| QLogic | Unknown | 10-Jan-2002 |
| QUALCOMM | Not Vulnerable | 19-Dec-2001 |
| Quallaby Corporation | Not Vulnerable | 27-Feb-2002 |
| Quick Eagle Networks | Not Vulnerable | 13-Mar-2002 |
| Quintom | Unknown | 14-Jan-2002 |
| RAD Data Communications | Not Vulnerable | 26-Mar-2002 |
| RADVISION | Unknown | 14-Jan-2002 |
| Radware | Vulnerable | 22-Mar-2002 |
| Red Hat, Inc. | Vulnerable | 8-Jan-2002 |
| Redback Networks Inc. | Vulnerable | 26-Feb-2002 |
| Rittal | Unknown | 21-Jan-2002 |
| Riverstone Networks | Vulnerable | 21-Feb-2002 |
| Samsung Electronics | Unknown | 10-Jan-2002 |
| SANavigator Inc. | Unknown | 10-Jan-2002 |
| Sasken | Unknown | 14-Jan-2002 |
| Satelcom | Unknown | 21-Jan-2002 |
| Scientific-Atlanta | Unknown | 14-Jan-2002 |
| SecureWorks | Unknown | 4-Mar-2002 |
| Sensorsoft Corporation | Unknown | 21-Jan-2002 |
| Sequent Computer Systems, Inc. | Unknown | 19-Dec-2001 |
| SGI | Unknown | 3-Jan-2002 |
| Sierra Wireless | Not Vulnerable | 14-Feb-2002 |
| Sinetica Corporation Limited | Not Vulnerable | 15-Oct-2002 |
| SMC Networks | Unknown | 11-Jan-2002 |
| Snap Server | Unknown | 4-Jan-2002 |
| Sniffer Technologies | Vulnerable | 7-Mar-2002 |
| SNMP Frameworks Inc. | Unknown | 10-Jan-2002 |
| SNMP Research | Vulnerable | 12-Feb-2002 |
| Software Technologies Group | Unknown | 15-Jan-2002 |
| SolarWinds.Net Inc. | Not Vulnerable | 5-Mar-2002 |
| SonicWALL INC. | Vulnerable | 25-Feb-2002 |
| Sonus Networks | Vulnerable | 26-Feb-2002 |
| Sony Corporation | Unknown | 19-Dec-2001 |
| Spider Software | Unknown | 21-Feb-2002 |
| Spirent Communications | Unknown | 10-Jan-2002 |
| Standard Networks Inc. | Not Vulnerable | 21-Feb-2002 |
| Stonesoft | Vulnerable | 6-Mar-2002 |
| StorageSoft Inc. | Unknown | 14-Jan-2002 |
| Stratus Technologies | Unknown | 14-Jan-2002 |
| Sun Microsystems, Inc. | Vulnerable | 27-Oct-2003 |
| Symantec Corporation | Vulnerable | 1-Apr-2003 |
| Sync Research Products | Unknown | 10-Jan-2002 |
| Tality Corporation | Unknown | 18-Jan-2002 |
| TANDBERG | Not Vulnerable | 13-Feb-2002 |
| Tavve Software Company | Not Vulnerable | 28-Mar-2002 |
| Telogy Networks | Unknown | 10-Jan-2002 |
| Telsey Telecommunications | Unknown | 14-Jan-2002 |
| Terayon | Unknown | 14-Jan-2002 |
| Texas Instruments Incorporated | Unknown | 14-Jan-2002 |
| The SCO Group (SCO Unix) | Vulnerable | 13-Sep-2002 |
| Tivoli Systems | Vulnerable | 3-Apr-2002 |
| TMP Consultoria S/C | Not Vulnerable | 21-Feb-2002 |
| TollBridge Technologies | Unknown | 14-Jan-2002 |
| Tollgrade Communications Inc. | Unknown | 21-Jan-2002 |
| Top Layer Networks | Not Vulnerable | 1-Apr-2002 |
| Toshiba International Corporation | Vulnerable | 16-Apr-2002 |
| Trend Micro | Not Vulnerable | 5-Mar-2002 |
| TRENDware International | Unknown | 14-Jan-2002 |
| Tripp Lite | Unknown | 15-Jan-2002 |
| Tut Systems Inc. | Unknown | 10-Jan-2002 |
| Unisphere Networks | Vulnerable | 22-Mar-2002 |
| Uptime Devices | Not Vulnerable | 6-Mar-2002 |
| Verilink | Unknown | 26-Mar-2002 |
| Veritas SOFTWARE | Vulnerable | 24-Apr-2002 |
| Vertical Networks Inc. | Vulnerable | 4-Aug-2003 |
| Vina Technologies | Vulnerable | 19-Apr-2002 |
| VIVE Synergies Inc. | Unknown | 14-Jan-2002 |
| Vixel | Unknown | 10-Jan-2002 |
| Vpacket Communications | Unknown | 14-Jan-2002 |
| Wailan Communications Inc. | Unknown | 10-Jan-2002 |
| Westell Technologies Inc | Unknown | 21-Jan-2002 |
| Western Telematic Inc. | Unknown | 14-Jan-2002 |
| Wind River Systems, Inc. | Vulnerable | 11-Mar-2002 |
| World Wide Packets | Vulnerable | 27-Feb-2002 |
| Xerox Corporation | Vulnerable | 1-Apr-2003 |
| Xspeed | Unknown | 10-Jan-2002 |
| Yipes | Unknown | 10-Jan-2002 |
| Zman Tikshuv Ltd. | Unknown | 21-Jan-2002 |
| ZyXEL | Unknown | 14-Jan-2002 |
References
http://www.cert.org/tech_tips/snmp_faq.html
http://www.kb.cert.org/vuls/id/854306
http://www.ee.oulu.fi/research/ouspg/protos/
http://www.cert.org/tech_tips/denial_of_service.html
http://www.ietf.org/rfc/rfc3000.txt
http://www.ietf.org/rfc/rfc1212.txt
http://www.ietf.org/rfc/rfc1213.txt
http://www.ietf.org/rfc/rfc1215.txt
http://www.ietf.org/rfc/rfc1270.txt
http://www.ietf.org/rfc/rfc2570.txt
http://www.ietf.org/rfc/rfc2571.txt
http://www.ietf.org/rfc/rfc2572.txt
http://www.ietf.org/rfc/rfc2573.txt
http://www.ietf.org/rfc/rfc2574.txt
http://www.ietf.org/rfc/rfc2575.txt
http://www.ietf.org/rfc/rfc2576.txt
http://www.securityfocus.com/bid/4088
http://online.securityfocus.com/bid/4132
http://online.securityfocus.com/bid/4732
Credit
The CERT Coordination Center thanks the Oulu University Secure Programming Group for reporting these vulnerabilities to us, for providing detailed technical analyses, and for assisting us in preparing this advisory. We also thank the many vendors who provided feedback regarding their respective vulnerabilities.
This document was written by Ian A. Finlay.
Other Information
| Date Public | 02/12/2002 |
| Date First Published | 02/12/2002 01:54:31 PM |
| Date Last Updated | 11/07/2007 |
| CERT Advisory | CA-2002-03 |
| CVE Name | CAN-2002-0012 |
| Metric | 69.25 |
| Document Revision | 48 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |