CVE-2015-8100

Name
CVE-2015-8100
Description
The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sensitive community information by reading this file.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MLIST http://www.openwall.com/lists/oss-security/2015/11/09/6
SECTRACK http://www.securitytracker.com/id/1034099
MISC http://packetstormsecurity.com/files/134323/OpenBSD-net-snmp-Information-Disclosure.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:net-snmp:net-snmp:*:*:*:*:*:*:*:* net-snmp >= None <= 5.8

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
net-snmp 3.12-main 5.8-r3 Carlo Landmeter <clandmeter@gmail.com> possibly vulnerable
net-snmp 3.11-main 5.8-r3 Carlo Landmeter <clandmeter@gmail.com> possibly vulnerable
net-snmp 3.17-main 5.9.3-r2 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
net-snmp 3.16-main 5.9.3-r1 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
net-snmp 3.15-main 5.9.3-r1 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
net-snmp 3.14-main 5.9.3-r1 Carlo Landmeter <clandmeter@alpinelinux.org> fixed