Debian: New net-snmp packages fix denial of service

A security vulnerability has been found in Net-SNMP releases that could allow a denial of service attack against Net-SNMP agent's that have opened a stream based protocol (eg TCP but not UDP). By default, Net-SNMP does not open a TCP port. Fixed packages are available from
Debian Security Advisory DSA 873-1                                        Martin Schulze
October 26th, 2005              
Package        : net-snmp
Vulnerability  : programming error
Problem type   : remote
Debian-specific: no
CVE ID         : CAN-2005-2177
BugTraq ID     : 14168

The old stable distribution (woody) does not contain a net-snmp package.

For the stable distribution (sarge) this problem has been fixed in
version 5.1.2-6.2.

For the unstable distribution (sid) this problem has been fixed in

We recommend that you upgrade your net-snmp package.

Upgrade Instructions
wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge
  Source archives:
  These files will probably be moved into the stable distribution on
  its next update.

Version: GnuPG v1.4.2 (GNU/Linux)


