Lucene search

K
vmwareVMwareVMSA-2010-0003.1
HistoryFeb 16, 2010 - 12:00 a.m.

VMSA-2010-0003.1 ESX Service Console update for net-snmp

2010-02-1600:00:00
www.vmware.com
18

0.049 Low

EPSS

Percentile

92.8%

a. Service Console package net-snmp updatedThis patch updates the service console package for net-snmp, net-snmp-utils, and net-snmp-libs to version net-snmp-5.0.9-2.30E.28. This net-snmp update fixes a divide-by- zero flaw in the snmpd daemon. A remote attacker could issue a specially crafted GETBULK request that could cause the snmpd daemon to fail. This vulnerability was introduced by an incorrect fix for CVE-2008-4309. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-1887 to this issue. Note: After installing the previous patch for net-snmp (ESX350-200901409-SG), running the snmpbulkwalk command with the parameter -CnX results in no output, and the snmpd daemon stops. The following table lists what action remediates the vulnerability (column 4) if a solution is available.