Re: Net-SNMP 5.9.5. and 5.10.pre2 released to address snmptrapd security vulnerability
Craig Small via Net-snmp-coders <[email protected]> Mon, 29 Dec 2025 10:03:03 +1100
| Newsgroups | gmane.network.net-snmp.devel |
|---|---|
| Message-ID | <CALy8Cw61WOvne8ZGBH_GtwPqEzm3bqaRs3BNNXdPArSggonF8g@mail.gmail.com> |
--===============5999398650220284311== Content-Type: multipart/alternative; boundary="0000000000009dbc2106470b21e5" --0000000000009dbc2106470b21e5 Content-Type: text/plain; charset="UTF-8" On Fri, 26 Dec 2025 at 10:23, Wes Hardaker <[email protected]> wrote: > Bart Van Assche via Net-snmp-coders > <[email protected]> writes: > > > One possible solution is to modify net-snmp-config such that all -W > > flags are filtered out. There may be better solutions. > > IMHO, the --enable-developer was created for adding options like this > and they should never be on anywhere in default builds. We should > remove all warning flags everywhere by default (IMHO, but that's the > point of a discussion: I could be alone in my thinking). > The net-snmp-config has had minor but long-lasting issues for years. It's one of those things I (as the Debian maintainer) keep coming back and then do nothing. Check out --agent-libs, for example: -Wl,-z,relro -Wl,-z,now -L/usr/lib/x86_64-linux-gnu -lnetsnmpmibs -lsensors -lpci -lm -lnetsnmpagent -lwrap -Wl,-E -lnetsnmp -lm -lssl -lssl -lssl -lssl -lcrypto That could be boiled down to -lnetsnmpmibs -lnetsnmpagent -lnetsnmp, which is what "pkg-config --libs netsnmp-agent" gives. No idea why it's got four libssl's I'm also not sure why net-snmp-config gives you one answer and pkg-config gives you a different answer. The standard way most people do is use pkg-config, but perhaps there's reasons for using the other way? - Craig BTW, 5.9.5.2 has been uploaded for Debian Sid. A patched 5.9.4 is uploaded but not available yet for Trixie, it's just gurgling through the release process. --0000000000009dbc2106470b21e5 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr">On Fri, 26 Dec 2025 at 10:23, Wes Hardake= r <<a href=3D"mailto:[email protected]">[email protected]= ceforge.net</a>> wrote:</div><div class=3D"gmail_quote gmail_quote_conta= iner"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;b= order-left:1px solid rgb(204,204,204);padding-left:1ex">Bart Van Assche via= Net-snmp-coders<br> <<a href=3D"mailto:[email protected]" target=3D"_bla= nk">[email protected]</a>> writes:<br> <br> > One possible solution is to modify net-snmp-config such that all -W<br= > > flags are filtered out. There may be better solutions.<br> <br> IMHO, the --enable-developer was created for adding options like this<br> and they should never be on anywhere in default builds.=C2=A0 We should<br> remove all warning flags everywhere by default (IMHO, but that's the<br= > point of a discussion: I could be alone in my thinking).<br></blockquote><d= iv>The net-snmp-config has had minor but long-lasting issues for years. It&= #39;s one of those things I (as the Debian maintainer) keep coming back and= then do nothing.</div><div>Check out --agent-libs, for example:</div><div>= -Wl,-z,relro -Wl,-z,now -L/usr/lib/x86_64-linux-gnu -lnetsnmpmibs -lsensors= -lpci -lm -lnetsnmpagent -lwrap -Wl,-E -lnetsnmp -lm -lssl -lssl -lssl -ls= sl -lcrypto</div><div>That could be boiled down to -lnetsnmpmibs -lnetsnmpa= gent -lnetsnmp, which is what "pkg-config --libs netsnmp-agent" g= ives.</div><div>No idea why=C2=A0it's got four libssl's</div><div><= br></div><div>I'm also not sure why net-snmp-config gives you one answe= r and pkg-config gives you a different answer.</div><div>The standard way m= ost people do is use pkg-config, but perhaps there's reasons for using = the other way?</div><div><br></div><div>=C2=A0- Craig</div><div><br></div>B= TW, 5.9.5.2 has been uploaded for Debian Sid. A patched 5.9.4 is uploaded b= ut not available yet for Trixie, it's just gurgling through the release= process.</div></div> --0000000000009dbc2106470b21e5-- --===============5999398650220284311== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============5999398650220284311== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Net-snmp-coders mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/net-snmp-coders --===============5999398650220284311==--