{
  "modified": "2025-08-09T19:01:27Z",
  "published": "2009-02-12T16:30:00Z",
  "id": "CVE-2008-6123",
  "details": "The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to \"source/destination IP address confusion.\"",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/34499"
    },
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/35416"
    },
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/35685"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.securitytracker.com/id?1021921"
    },
    {
      "type": "ARTICLE",
      "url": "http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html"
    },
    {
      "type": "ARTICLE",
      "url": "http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00002.html"
    },
    {
      "type": "ARTICLE",
      "url": "http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00003.html"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2009/02/12/2"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2009/02/12/4"
    },
    {
      "type": "ARTICLE",
      "url": "http://www.openwall.com/lists/oss-security/2009/02/12/7"
    },
    {
      "type": "EVIDENCE",
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=250429"
    },
    {
      "type": "FIX",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=485211"
    },
    {
      "type": "REPORT",
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=250429"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=485211"
    },
    {
      "type": "WEB",
      "url": "http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/trunk/net-snmp/snmplib/snmpUDPDomain.c?r1=17325\u0026r2=17367\u0026pathrev=17367"
    },
    {
      "type": "WEB",
      "url": "http://net-snmp.svn.sourceforge.net/viewvc/net-snmp?view=rev\u0026revision=17367"
    },
    {
      "type": "WEB",
      "url": "http://www.redhat.com/support/errata/RHSA-2009-0295.html"
    },
    {
      "type": "WEB",
      "url": "http://www.securitytracker.com/id?1021921"
    },
    {
      "type": "WEB",
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10289"
    }
  ]
}
