Vulnerability CVE-2020-24361: Information
Description
SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: HIGH (7.5)
Vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:P
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| snmptt | sisyphus | 1.4.2-alt1 | 1.5-alt1 | ALT-PU-2020-3129-1 | 260492 | Fixed |
| snmptt | p11 | 1.4.2-alt1 | 1.4.2-alt1 | ALT-PU-2020-3129-1 | 260492 | Fixed |
| snmptt | p10 | 1.4.2-alt1 | 1.4.2-alt1 | ALT-PU-2020-3129-1 | 260492 | Fixed |
| snmptt | p9 | 1.4.2-alt1 | 1.4.2-alt1 | ALT-PU-2020-3174-1 | 260493 | Fixed |
| snmptt | c10f2 | 1.4.2-alt1 | 1.4.2-alt1 | ALT-PU-2020-3129-1 | 260492 | Fixed |
| snmptt | c9f2 | 1.4.2-alt1 | 1.4.2-alt1 | ALT-PU-2024-3798-3 | 342504 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
|---|---|
| http://www.snmptt.org/changelog.shtml |
|
| https://lists.debian.org/debian-lts-announce/2020/10/msg00006.html |
|
| https://security.gentoo.org/glsa/202007-63 |
|
| BDU:2021-03734 |