Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1019791 > unrolled thread

Bug#966544: snmpd: extend option broken after update

Started byJames Greig <james@host-it.co.uk>
First post2020-07-30 15:10 +0200
Last post2020-08-03 19:00 +0200
Articles 16 — 11 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#966544: snmpd: extend option broken after update James Greig <james@host-it.co.uk> - 2020-07-30 15:10 +0200
    Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update Craig Small <csmall@debian.org> - 2020-07-31 03:00 +0200
      Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update James Greig <James@host-it.co.uk> - 2020-07-31 10:00 +0200
    Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update Christian Balzer <chibi@gol.com> - 2020-07-31 05:40 +0200
      Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update Axel Uhl <axel.uhl@gmx.de> - 2020-08-01 18:00 +0200
    Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update Albertas Sileika <a.sileika@gmail.com> - 2020-07-31 06:20 +0200
      Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update Craig Small <csmall@debian.org> - 2020-07-31 06:30 +0200
        Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update Albertas Sileika <a.sileika@gmail.com> - 2020-07-31 06:40 +0200
        Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option  broken after update Ramon Cahenzli <rca@psy-q.ch> - 2020-07-31 09:10 +0200
    Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update Rudi Daemen <info@kratjebierhosting.nl> - 2020-07-31 10:10 +0200
    Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update Zubrick <zubrick@number6.ch> - 2020-07-31 11:40 +0200
    Bug#966544: snmpd: extend option broken after update Salvatore Bonaccorso <carnil@debian.org> - 2020-08-01 08:40 +0200
      Bug#966544: snmpd: extend option broken after update James Greig <James@host-it.co.uk> - 2020-08-01 18:40 +0200
      Bug#966544: snmpd: extend option broken after update Salvatore Bonaccorso <carnil@debian.org> - 2020-08-04 19:20 +0200
        Bug#966544: snmpd: extend option broken after update James Greig <James@host-it.co.uk> - 2020-08-04 20:40 +0200
    Bug#966544: Switching from extend to pass for custom endpoints Ian Campbell <ijc@debian.org> - 2020-08-03 19:00 +0200

#1019791 — Bug#966544: snmpd: extend option broken after update

FromJames Greig <james@host-it.co.uk>
Date2020-07-30 15:10 +0200
SubjectBug#966544: snmpd: extend option broken after update
Message-ID<AygtP-5Es-1@gated-at.bofh.it>
Package: snmpd
Version: 5.7.3+dfsg-1.7+deb9u2
Severity: important

Dear Maintainer,

*** Reporter, please consider answering these questions, where appropriate ***

Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system
breaks the ability to use 'extend' in snmpd.

After updating on any stretch system and restarting snmpd this error will appear:-

Warning: Unknown token: extend

It's likely the latest binary build of this package has not included options to
enable extend and/or other extras.

*** End of the template - remove these template lines ***


-- System Information:
Debian Release: 9.13
  APT prefers oldstable-updates
  APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en_GB:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages snmpd depends on:
ii  adduser                3.115
ii  debconf [debconf-2.0]  1.5.61
ii  init-system-helpers    1.48
ii  libc6                  2.24-11+deb9u4
ii  libsnmp-base           5.7.3+dfsg-1.7+deb9u2
ii  libsnmp30              5.7.3+dfsg-1.7+deb9u2
ii  lsb-base               9.20161125

snmpd recommends no packages.

Versions of packages snmpd suggests:
pn  snmptrapd  <none>

-- debconf information excluded

[toc] | [next] | [standalone]


#1019876 — Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update

FromCraig Small <csmall@debian.org>
Date2020-07-31 03:00 +0200
SubjectBug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update
Message-ID<AyryV-3Ex-1@gated-at.bofh.it>
In reply to#1019791

[Multipart message — attachments visible in raw view] — view raw

Hi James,
  That would have been intentional, the EXTEND MIB has major security
issues.

 - Craig


On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote:

> Package: snmpd
> Version: 5.7.3+dfsg-1.7+deb9u2
> Severity: important
>
> Dear Maintainer,
>
> *** Reporter, please consider answering these questions, where appropriate
> ***
>
> Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system
> breaks the ability to use 'extend' in snmpd.
>
> After updating on any stretch system and restarting snmpd this error will
> appear:-
>
> Warning: Unknown token: extend
>
> It's likely the latest binary build of this package has not included
> options to
> enable extend and/or other extras.
>
> *** End of the template - remove these template lines ***
>
>
> -- System Information:
> Debian Release: 9.13
>   APT prefers oldstable-updates
>   APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
> Architecture: amd64 (x86_64)
>
> Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores)
> Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8),
> LANGUAGE=en_GB:en (charmap=UTF-8)
> Shell: /bin/sh linked to /bin/dash
> Init: systemd (via /run/systemd/system)
>
> Versions of packages snmpd depends on:
> ii  adduser                3.115
> ii  debconf [debconf-2.0]  1.5.61
> ii  init-system-helpers    1.48
> ii  libc6                  2.24-11+deb9u4
> ii  libsnmp-base           5.7.3+dfsg-1.7+deb9u2
> ii  libsnmp30              5.7.3+dfsg-1.7+deb9u2
> ii  lsb-base               9.20161125
>
> snmpd recommends no packages.
>
> Versions of packages snmpd suggests:
> pn  snmptrapd  <none>
>
> -- debconf information excluded
>
> _______________________________________________
> Pkg-net-snmp-devel mailing list
> Pkg-net-snmp-devel@alioth-lists.debian.net
> https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-net-snmp-devel

[toc] | [prev] | [next] | [standalone]


#1019904 — Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update

FromJames Greig <James@host-it.co.uk>
Date2020-07-31 10:00 +0200
SubjectBug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update
Message-ID<Ayy7n-7IG-1@gated-at.bofh.it>
In reply to#1019876

[Multipart message — attachments visible in raw view] — view raw

Hi,

Though I do appreciate that security should come above everything.  I have to agree with everyone else here it seems surprising  that it has just been removed like this.  We use it in read-only ourselves as well and it has broken a lot of monitoring.

Kind regards

James Greig
From: Craig Small <csmall@debian.org>
Sent: 31 July 2020 01:46
To: James Greig <James@host-it.co.uk>; 966544@bugs.debian.org
Subject: Re: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update

Hi James,
  That would have been intentional, the EXTEND MIB has major security issues.

 - Craig


On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk<mailto:james@host-it.co.uk>> wrote:
Package: snmpd
Version: 5.7.3+dfsg-1.7+deb9u2
Severity: important

Dear Maintainer,

*** Reporter, please consider answering these questions, where appropriate ***

Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system
breaks the ability to use 'extend' in snmpd.

After updating on any stretch system and restarting snmpd this error will appear:-

Warning: Unknown token: extend

It's likely the latest binary build of this package has not included options to
enable extend and/or other extras.

*** End of the template - remove these template lines ***


-- System Information:
Debian Release: 9.13
  APT prefers oldstable-updates
  APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en_GB:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages snmpd depends on:
ii  adduser                3.115
ii  debconf [debconf-2.0]  1.5.61
ii  init-system-helpers    1.48
ii  libc6                  2.24-11+deb9u4
ii  libsnmp-base           5.7.3+dfsg-1.7+deb9u2
ii  libsnmp30              5.7.3+dfsg-1.7+deb9u2
ii  lsb-base               9.20161125

snmpd recommends no packages.

Versions of packages snmpd suggests:
pn  snmptrapd  <none>

-- debconf information excluded

_______________________________________________
Pkg-net-snmp-devel mailing list
Pkg-net-snmp-devel@alioth-lists.debian.net<mailto:Pkg-net-snmp-devel@alioth-lists.debian.net>
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-net-snmp-devel

[toc] | [prev] | [next] | [standalone]


#1019883 — Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update

FromChristian Balzer <chibi@gol.com>
Date2020-07-31 05:40 +0200
SubjectBug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update
Message-ID<Ayu3L-5jm-5@gated-at.bofh.it>
In reply to#1019791
Hello Craig,

These issues, do they warrant utterly breaking things w/o any recourse
short of recompiling things for many, many users that use the extend
feature?
Especially given the fact that SNMP traffic tends to be on private
networks and the feature not being enabled by default in the config.

At the very least a "this will break things, abort now" missive during
upgrade would have been nice.

If upstream can't/won't fix this snmpd has lost it's usefulness for me in
the long run compared to other data collectors.

Regards,

Christian


On Fri, 31 Jul 2020 10:46:29 +1000 Craig Small <csmall@debian.org> wrote:
> Hi James,
>   That would have been intentional, the EXTEND MIB has major security
> issues.
> 
>  - Craig
> 
> 
> On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote:
> 
> > Package: snmpd
> > Version: 5.7.3+dfsg-1.7+deb9u2
> > Severity: important
> >
> > Dear Maintainer,
> >
> > *** Reporter, please consider answering these questions, where appropriate
> > ***
> >
> > Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system
> > breaks the ability to use 'extend' in snmpd.
> >
> > After updating on any stretch system and restarting snmpd this error will
> > appear:-
> >
> > Warning: Unknown token: extend
> >
> > It's likely the latest binary build of this package has not included
> > options to
> > enable extend and/or other extras.
> >
> > *** End of the template - remove these template lines ***
> >
> >
> > -- System Information:
> > Debian Release: 9.13
> >   APT prefers oldstable-updates
> >   APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
> > Architecture: amd64 (x86_64)
> >
> > Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores)
> > Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8),
> > LANGUAGE=en_GB:en (charmap=UTF-8)
> > Shell: /bin/sh linked to /bin/dash
> > Init: systemd (via /run/systemd/system)
> >
> > Versions of packages snmpd depends on:
> > ii  adduser                3.115
> > ii  debconf [debconf-2.0]  1.5.61
> > ii  init-system-helpers    1.48
> > ii  libc6                  2.24-11+deb9u4
> > ii  libsnmp-base           5.7.3+dfsg-1.7+deb9u2
> > ii  libsnmp30              5.7.3+dfsg-1.7+deb9u2
> > ii  lsb-base               9.20161125
> >
> > snmpd recommends no packages.
> >
> > Versions of packages snmpd suggests:
> > pn  snmptrapd  <none>
> >
> > -- debconf information excluded

-- 
Christian Balzer        Network/Systems Engineer                
chibi@gol.com   	Rakuten Mobile Inc.

[toc] | [prev] | [next] | [standalone]


#1020070 — Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update

FromAxel Uhl <axel.uhl@gmx.de>
Date2020-08-01 18:00 +0200
SubjectBug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update
Message-ID<Az25s-1Ek-7@gated-at.bofh.it>
In reply to#1019883

[Multipart message — attachments visible in raw view] — view raw

Same here. snmpd broke over night, now my mrtg which is reporting, e.g., 
disk temperatures using a smartctl-based cannot be reported anymore, and 
I was wondering why this cron job now keeps flooding my inbox... All 
intranet, all very inconvenient. As others mentioned, a warning would 
have been nice. Now I need to compile from sources. What a hassle!

On Fri, 31 Jul 2020 12:32:05 +0900 Christian Balzer <chibi@gol.com> wrote:
> 
> Hello Craig,
> 
> These issues, do they warrant utterly breaking things w/o any recourse
> short of recompiling things for many, many users that use the extend
> feature?
> Especially given the fact that SNMP traffic tends to be on private
> networks and the feature not being enabled by default in the config.
> 
> At the very least a "this will break things, abort now" missive during
> upgrade would have been nice.
> 
> If upstream can't/won't fix this snmpd has lost it's usefulness for me in
> the long run compared to other data collectors.
> 
> Regards,
> 
> Christian
> 
> 
> On Fri, 31 Jul 2020 10:46:29 +1000 Craig Small <csmall@debian.org> wrote:
> > Hi James,
> >   That would have been intentional, the EXTEND MIB has major security
> > issues.
> > 
> >  - Craig
> > 
> > 
> > On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote:
> > 
> > > Package: snmpd
> > > Version: 5.7.3+dfsg-1.7+deb9u2
> > > Severity: important
> > >
> > > Dear Maintainer,
> > >
> > > *** Reporter, please consider answering these questions, where appropriate
> > > ***
> > >
> > > Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system
> > > breaks the ability to use 'extend' in snmpd.
> > >
> > > After updating on any stretch system and restarting snmpd this error will
> > > appear:-
> > >
> > > Warning: Unknown token: extend
> > >
> > > It's likely the latest binary build of this package has not included
> > > options to
> > > enable extend and/or other extras.
> > >
> > > *** End of the template - remove these template lines ***
> > >
> > >
> > > -- System Information:
> > > Debian Release: 9.13
> > >   APT prefers oldstable-updates
> > >   APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
> > > Architecture: amd64 (x86_64)
> > >

[toc] | [prev] | [next] | [standalone]


#1019886 — Bug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update

FromAlbertas Sileika <a.sileika@gmail.com>
Date2020-07-31 06:20 +0200
SubjectBug#966544: [Pkg-net-snmp-devel] Bug#966544: snmpd: extend option broken after update
Message-ID<AyuGt-5Lv-1@gated-at.bofh.it>
In reply to#1019791

[Multipart message — attachments visible in raw view] — view raw

Hi,

It is not acceptable to remove feature without possibility to enable it
again. This update breaks part of our monitoring system.

Albertas

On Fri, 31 Jul 2020 10:46:29 +1000 Craig Small <csmall@debian.org> wrote:
> Hi James,
> That would have been intentional, the EXTEND MIB has major security
> issues.
>
> - Craig
>
>
> On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote:
>
> > Package: snmpd
> > Version: 5.7.3+dfsg-1.7+deb9u2
> > Severity: important
> >
> > Dear Maintainer,
> >
> > *** Reporter, please consider answering these questions, where
appropriate
> > ***
> >
> > Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system
> > breaks the ability to use 'extend' in snmpd.
> >
> > After updating on any stretch system and restarting snmpd this error
will
> > appear:-
> >
> > Warning: Unknown token: extend
> >
> > It's likely the latest binary build of this package has not included
> > options to
> > enable extend and/or other extras.
> >
> > *** End of the template - remove these template lines ***
> >
> >
> > -- System Information:
> > Debian Release: 9.13
> > APT prefers oldstable-updates
> > APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
> > Architecture: amd64 (x86_64)
> >
> > Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores)
> > Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8),
> > LANGUAGE=en_GB:en (charmap=UTF-8)
> > Shell: /bin/sh linked to /bin/dash
> > Init: systemd (via /run/systemd/system)
> >
> > Versions of packages snmpd depends on:
> > ii adduser 3.115
> > ii debconf [debconf-2.0] 1.5.61
> > ii init-system-helpers 1.48
> > ii libc6 2.24-11+deb9u4
> > ii libsnmp-base 5.7.3+dfsg-1.7+deb9u2
> > ii libsnmp30 5.7.3+dfsg-1.7+deb9u2
> > ii lsb-base 9.20161125
> >
> > snmpd recommends no packages.
> >
> > Versions of packages snmpd suggests:
> > pn snmptrapd <none>
> >
> > -- debconf information excluded


-- 
Su pagarba,
Albertas Šileika

[toc] | [prev] | [next] | [standalone]


#1019887 — Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update

FromCraig Small <csmall@debian.org>
Date2020-07-31 06:30 +0200
SubjectBug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update
Message-ID<AyuQ9-5RC-1@gated-at.bofh.it>
In reply to#1019886

[Multipart message — attachments visible in raw view] — view raw

I'm trying to understand why you (or anyone) would use such an insecure
feature.  One question, are you using in read-only mode or read-write mode?
read-only mode could be enabled, but read-write probably can't be anymore.

 - Craig


On Fri, 31 Jul 2020 at 14:15, Albertas Sileika <a.sileika@gmail.com> wrote:

> Hi,
>
> It is not acceptable to remove feature without possibility to enable it
> again. This update breaks part of our monitoring system.
>
> Albertas
>
> On Fri, 31 Jul 2020 10:46:29 +1000 Craig Small <csmall@debian.org> wrote:
> > Hi James,
> > That would have been intentional, the EXTEND MIB has major security
> > issues.
> >
> > - Craig
> >
> >
> > On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote:
> >
> > > Package: snmpd
> > > Version: 5.7.3+dfsg-1.7+deb9u2
> > > Severity: important
> > >
> > > Dear Maintainer,
> > >
> > > *** Reporter, please consider answering these questions, where
> appropriate
> > > ***
> > >
> > > Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system
> > > breaks the ability to use 'extend' in snmpd.
> > >
> > > After updating on any stretch system and restarting snmpd this error
> will
> > > appear:-
> > >
> > > Warning: Unknown token: extend
> > >
> > > It's likely the latest binary build of this package has not included
> > > options to
> > > enable extend and/or other extras.
> > >
> > > *** End of the template - remove these template lines ***
> > >
> > >
> > > -- System Information:
> > > Debian Release: 9.13
> > > APT prefers oldstable-updates
> > > APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
> > > Architecture: amd64 (x86_64)
> > >
> > > Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores)
> > > Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8),
> > > LANGUAGE=en_GB:en (charmap=UTF-8)
> > > Shell: /bin/sh linked to /bin/dash
> > > Init: systemd (via /run/systemd/system)
> > >
> > > Versions of packages snmpd depends on:
> > > ii adduser 3.115
> > > ii debconf [debconf-2.0] 1.5.61
> > > ii init-system-helpers 1.48
> > > ii libc6 2.24-11+deb9u4
> > > ii libsnmp-base 5.7.3+dfsg-1.7+deb9u2
> > > ii libsnmp30 5.7.3+dfsg-1.7+deb9u2
> > > ii lsb-base 9.20161125
> > >
> > > snmpd recommends no packages.
> > >
> > > Versions of packages snmpd suggests:
> > > pn snmptrapd <none>
> > >
> > > -- debconf information excluded
>
>
> --
> Su pagarba,
> Albertas Šileika
> _______________________________________________
> Pkg-net-snmp-devel mailing list
> Pkg-net-snmp-devel@alioth-lists.debian.net
> https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-net-snmp-devel

[toc] | [prev] | [next] | [standalone]


#1019888 — Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update

FromAlbertas Sileika <a.sileika@gmail.com>
Date2020-07-31 06:40 +0200
SubjectBug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update
Message-ID<AyuZP-5UT-1@gated-at.bofh.it>
In reply to#1019887

[Multipart message — attachments visible in raw view] — view raw

We use read-only mode for monitoring custom things with nagios.
Maybe it is possible to disable extend by default, but to leave possibility
to enable it. In our case it is enough to have read-only mode.

Albertas

On Fri, Jul 31, 2020 at 7:18 AM Craig Small <csmall@debian.org> wrote:

> I'm trying to understand why you (or anyone) would use such an insecure
> feature.  One question, are you using in read-only mode or read-write mode?
> read-only mode could be enabled, but read-write probably can't be anymore.
>
>  - Craig
>
>
> On Fri, 31 Jul 2020 at 14:15, Albertas Sileika <a.sileika@gmail.com>
> wrote:
>
>> Hi,
>>
>> It is not acceptable to remove feature without possibility to enable it
>> again. This update breaks part of our monitoring system.
>>
>> Albertas
>>
>> On Fri, 31 Jul 2020 10:46:29 +1000 Craig Small <csmall@debian.org> wrote:
>> > Hi James,
>> > That would have been intentional, the EXTEND MIB has major security
>> > issues.
>> >
>> > - Craig
>> >
>> >
>> > On Thu, 30 Jul 2020 at 23:03, James Greig <james@host-it.co.uk> wrote:
>> >
>> > > Package: snmpd
>> > > Version: 5.7.3+dfsg-1.7+deb9u2
>> > > Severity: important
>> > >
>> > > Dear Maintainer,
>> > >
>> > > *** Reporter, please consider answering these questions, where
>> appropriate
>> > > ***
>> > >
>> > > Updating snmpd from deb9u1 to deb9u2 via apt on any stretch system
>> > > breaks the ability to use 'extend' in snmpd.
>> > >
>> > > After updating on any stretch system and restarting snmpd this error
>> will
>> > > appear:-
>> > >
>> > > Warning: Unknown token: extend
>> > >
>> > > It's likely the latest binary build of this package has not included
>> > > options to
>> > > enable extend and/or other extras.
>> > >
>> > > *** End of the template - remove these template lines ***
>> > >
>> > >
>> > > -- System Information:
>> > > Debian Release: 9.13
>> > > APT prefers oldstable-updates
>> > > APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
>> > > Architecture: amd64 (x86_64)
>> > >
>> > > Kernel: Linux 4.9.0-13-amd64 (SMP w/8 CPU cores)
>> > > Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8),
>> > > LANGUAGE=en_GB:en (charmap=UTF-8)
>> > > Shell: /bin/sh linked to /bin/dash
>> > > Init: systemd (via /run/systemd/system)
>> > >
>> > > Versions of packages snmpd depends on:
>> > > ii adduser 3.115
>> > > ii debconf [debconf-2.0] 1.5.61
>> > > ii init-system-helpers 1.48
>> > > ii libc6 2.24-11+deb9u4
>> > > ii libsnmp-base 5.7.3+dfsg-1.7+deb9u2
>> > > ii libsnmp30 5.7.3+dfsg-1.7+deb9u2
>> > > ii lsb-base 9.20161125
>> > >
>> > > snmpd recommends no packages.
>> > >
>> > > Versions of packages snmpd suggests:
>> > > pn snmptrapd <none>
>> > >
>> > > -- debconf information excluded
>>
>>
>> --
>> Su pagarba,
>> Albertas Šileika
>> _______________________________________________
>> Pkg-net-snmp-devel mailing list
>> Pkg-net-snmp-devel@alioth-lists.debian.net
>>
>> https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-net-snmp-devel
>
>

-- 
Su pagarba,
Albertas Šileika

[toc] | [prev] | [next] | [standalone]


#1019901 — Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update

FromRamon Cahenzli <rca@psy-q.ch>
Date2020-07-31 09:10 +0200
SubjectBug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update
Message-ID<AyxkZ-7sv-5@gated-at.bofh.it>
In reply to#1019887
Hi Craig,

On Fri, 31 Jul 2020 14:17:46 +1000 Craig Small <csmall@debian.org>
wrote:
> I'm trying to understand why you (or anyone) would use such an
> insecure feature.  One question, are you using in read-only mode or
> read-write mode? 

We also use this feature in read-only mode for monitoring, and I woke
up to hundreds of red sensors this morning after unattended-upgrades
pulled in the new version.

Am I looking in the wrong place or is there no mention of this change
in the changelog?

Cheers,

Ramon

[toc] | [prev] | [next] | [standalone]


#1019906 — Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update

FromRudi Daemen <info@kratjebierhosting.nl>
Date2020-07-31 10:10 +0200
SubjectBug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update
Message-ID<Ayyh3-81j-5@gated-at.bofh.it>
In reply to#1019791

[Multipart message — attachments visible in raw view] — view raw

Hi, 

same here, woke up this morning to dozens of alert emails because extend
support is suddenly "removed" without any change logs indicating this,
nor in the man pages. 

The snmpd runs in read-only mode here as well. 

Alternatively, can you please provide a valid method of getting extended
data into snmpd with the same ease as 'extend' feature offered? 

Kind regards,
Rudi Daemen

[toc] | [prev] | [next] | [standalone]


#1019920 — Bug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update

FromZubrick <zubrick@number6.ch>
Date2020-07-31 11:40 +0200
SubjectBug#966544: [Pkg-net-snmp-devel] Bug#966544: Bug#966544: snmpd: extend option broken after update
Message-ID<AyzG9-j6-13@gated-at.bofh.it>
In reply to#1019791

[Multipart message — attachments visible in raw view] — view raw

Hi,

Same here for all the nagios alerts, and we don't have any writable snmp
instance in our infrastructure only read-only.

What is to question is that the original bug #965166 that implied this
update proposed three different fixes that didn't imply breaking
production servers and none of these fixes seem to have been considered.
 

Disabling a feature on stable or old-stable and preventing enabling it
back seems to be the worst fix possible for me. This would be a suitable
change for a testing version.

Regards 

Zubrick

[toc] | [prev] | [next] | [standalone]


#1020025

FromSalvatore Bonaccorso <carnil@debian.org>
Date2020-08-01 08:40 +0200
Message-ID<AyTlv-40n-1@gated-at.bofh.it>
In reply to#1019791
Hi Felix and all,

On Fri, Jul 31, 2020 at 03:36:54PM +0200, Felix Sperling wrote:
> Hi,
> 
> we were also effected from the update 5.7.3+dfsg-1.7+deb9u2 causing lots of
> broken icinga checks.
> 
> Our workaround is pinning 5.7.3+dfsg-1.7+deb9u1.
> 
> What's unclear from the solution if 5.8 also will be available in stretch
> and buster which we need. Otherwise it would be great to enable extend in
> 5.7.3 for those versions.

5.8+dfsg-5 cannot go to buster and stretch, so this is not an option.
For buster the update the maintainer (Craig Small) is planning for the
security update is mirroring what went into unstable.

As 5.7.3+dfsg-1.7+deb9u2 went out as DLA 2299-1, I'm looping in here
the LTS team. LTS team: Would suggest to issue a regression update for
the DLA and revisit the fix for CVE-2020-15862 to do the same, not to
disable EXTEND-MIB completely but making it read-only.

Hope this helps so far,

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#1020074

FromJames Greig <James@host-it.co.uk>
Date2020-08-01 18:40 +0200
Message-ID<Az2Ia-29W-3@gated-at.bofh.it>
In reply to#1020025
Hi,

Well, hopefully LTS can fix this for those of us that are using oldstable (stretch).  It almost seems like someone broke production on the oldstable version, then said, "don't worry - we've fixed it on unstable" (a version no one is using in production), then walked away :) 

Current work around is to either apt-mark snmpd before you upgrade if you haven't already broken it OR to run something like apt install snmpd=5.7.3+dfsg-1.7+deb9u1 libsnmp30=5.7.3+dfsg-1.7+deb9u1 to force the downgrade.

Kind regards

James Greig

[toc] | [prev] | [next] | [standalone]


#1020554

FromSalvatore Bonaccorso <carnil@debian.org>
Date2020-08-04 19:20 +0200
Message-ID<AA8Lv-2JX-7@gated-at.bofh.it>
In reply to#1020025
Hi Felix and all,

On Sat, Aug 01, 2020 at 08:37:17AM +0200, Salvatore Bonaccorso wrote:
> Hi Felix and all,
> 
> On Fri, Jul 31, 2020 at 03:36:54PM +0200, Felix Sperling wrote:
> > Hi,
> > 
> > we were also effected from the update 5.7.3+dfsg-1.7+deb9u2 causing lots of
> > broken icinga checks.
> > 
> > Our workaround is pinning 5.7.3+dfsg-1.7+deb9u1.
> > 
> > What's unclear from the solution if 5.8 also will be available in stretch
> > and buster which we need. Otherwise it would be great to enable extend in
> > 5.7.3 for those versions.
> 
> 5.8+dfsg-5 cannot go to buster and stretch, so this is not an option.
> For buster the update the maintainer (Craig Small) is planning for the
> security update is mirroring what went into unstable.
> 
> As 5.7.3+dfsg-1.7+deb9u2 went out as DLA 2299-1, I'm looping in here
> the LTS team. LTS team: Would suggest to issue a regression update for
> the DLA and revisit the fix for CVE-2020-15862 to do the same, not to
> disable EXTEND-MIB completely but making it read-only.

This should be handled with DLA 2313-1[1].

 [1] https://lists.debian.org/debian-lts-announce/2020/08/msg00009.html

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#1020565

FromJames Greig <James@host-it.co.uk>
Date2020-08-04 20:40 +0200
Message-ID<AAa0W-3pS-21@gated-at.bofh.it>
In reply to#1020554
Hi,

Thanks to the LTS team for resolving for those on stretch.

Kind regards

James Greig 

[toc] | [prev] | [next] | [standalone]


#1020405 — Bug#966544: Switching from extend to pass for custom endpoints

FromIan Campbell <ijc@debian.org>
Date2020-08-03 19:00 +0200
SubjectBug#966544: Switching from extend to pass for custom endpoints
Message-ID<AzLYB-5qp-1@gated-at.bofh.it>
In reply to#1019791
Hi all,

I switched from pass to extend for my custom endpoint since the latter
was not disabled with the security update. It's a bit more faff but not
intractable (just lots of boilerplate really) so maybe it's useful to
post here as a sort of recipe while things get sorted out some other
way in the packaging.

I went from snmpd.conf with (nb: /var/run/qcontrol.temp simply contains
a single integer value, nothing fancy, it's updated elsewhere):

   extend     .1.3.6.1.4.1.65535.1 - /bin/cat /var/run/qcontrol.temp

To one with:

   pass .1.3.6.1.4.1.65535.1 /bin/bash /etc/snmp/qcontrol-mib

Where /etc/snmp/qcontrol-mib is:

   #!/bin/bash

   # https://sourceforge.net/p/net-snmp/code/ci/master/tree/local/passtest

PLACE=".1.3.6.1.4.1.65535.1"
OP="$1"
REQ="$2"

case "$OP" in
"-s") # SET
        OP="SET"
        logger -p daemon.debug "qcontrol-mib: $OP $REQ: ignored"
        exit 0
        ;;
"-n") # GETNEXT
        OP="GETNEXT"
        case "$REQ" in
        $PLACE|$PLACE.0|$PLACE.0.*|$PLACE.1) RET="$PLACE.1.0" ;;
        *) exit 0 ;; # Nothing after this
        esac
        ;;
"-g") # GET
        OP="GET"
        case "$REQ" in
        $PLACE.1.0) RET="$REQ" ;;
        *)
                logger -p daemon.warn "qcontrol-mib: $OP $REQ: unknown"
                exit 0
                ;;
        esac
        ;;
esac

# GET and GETNEXT
logger -p daemon.debug "qcontrol-mib: $OP $REQ: OK"
echo "$RET"
case "$RET" in
$PLACE.1.0) echo "integer" ; printf "%d\n" $(cat /var/run/qcontrol.temp);;
esac

These were moderately useful resources:

   http://www.net-snmp.org/docs/man/snmpd.conf.html (see: MIB-Specific Extension Commands)
   http://net-snmp.sourceforge.net/wiki/index.php/Tut:Extending_snmpd_using_shell_scripts
https://sourceforge.net/p/net-snmp/code/ci/master/tree/local/passtest

For people who want persistent_pass instead this looked like a good
resource but I didn't follow it myself since my needs were so trivial:
   https://vincent.bernat.ch/en/blog/2012-extending-netsnmp

That has links to Perl and Python helper libraries which I think you'd
likely want to use if you wanted multiple values since plumbing the
GETNEXT stuff together manually in the simple shell script case as
above would be fairly tedious.

HTH someone,
Ian.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web