[nsp] recent SNMP vulnerability vs 12.1(13)E14

Kinczli Zoltán Zoltan.Kinczli at Synergon.hu
Fri Apr 23 04:37:41 EDT 2004


hello,
 
  Is 12.1(13)E14 affected by the latest SNMP vulnerability?
 
The picture is not clear for me, since the vulnerable code was introduced by  CSCeb22276 fix.
 CSCeb22276  is first integrated into the 12.1E train in the interim maintenance release of  12.1(19.4)E
 
Having said that, it's strange that the  <http://www.cisco.com/warp/public/707/cisco-sa-20040420-snmp.shtml> http://www.cisco.com/warp/public/707/cisco-sa-20040420-snmp.shtml announcement
says that  12.1(20)E3 and 12.1(22)E1 are the repaired, and it doesn't mentions 12.1(13)E rebuilds. I feel their are not
vulnerabel, but more stable.
 
I guess, i'm not the only one who prefers E14 over E3 (not to mention the E1)... be it any maintenance version.
 
Can someone from Cisco confirm that for me, pls!
 
rgds
  -zoltan


More information about the cisco-nsp mailing list