A denial of service vulnerability was discovered in how Net-SNMP
processed GETBULK requests. A remote attacker with read access to
the SNMP server could issue a specially-crafted request which would
cause snmpd to crash (CVE-2008-4309).
Please note that for this to be successfully exploited, an attacker
must have read access to the SNMP server. By default, the public
community name grants read-only access, however it is recommended
that the default community name be changed in production.
The updated packages have been patched to correct this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2008-4309
_______________________________________________________________________