Insecure default bsnmpd.conf permissions (CVE-2015-5677)

Andrea Brancatelli abrancatelli at schema31.it
Thu Jan 14 12:01:56 UTC 2016


Hello everybody. 

I just read the above security advisory. In the solution it says:

"This vulnerability can be fixed by modifying the permission on
/etc/bsnmpd.conf to owner root:wheel and permission 0600."

I guess it's a typo and the correct filename is /etc/snmpd.config,
right? There's no /etc/bsnmpd.conf in the default config...

Thanks.

-- 

Andrea Brancatelli

 


More information about the freebsd-stable mailing list