Re: Net-SNMP 5.9.5. and 5.10.pre2 released to address snmptrapd security vulnerability

Craig Small via Net-snmp-coders <[email protected]> Mon, 29 Dec 2025 10:03:03 +1100
Newsgroups gmane.network.net-snmp.devel
Message-ID <CALy8Cw61WOvne8ZGBH_GtwPqEzm3bqaRs3BNNXdPArSggonF8g@mail.gmail.com>
--===============5999398650220284311==
Content-Type: multipart/alternative; boundary="0000000000009dbc2106470b21e5"

--0000000000009dbc2106470b21e5
Content-Type: text/plain; charset="UTF-8"

On Fri, 26 Dec 2025 at 10:23, Wes Hardaker <[email protected]>
wrote:

> Bart Van Assche via Net-snmp-coders
> <[email protected]> writes:
>
> > One possible solution is to modify net-snmp-config such that all -W
> > flags are filtered out. There may be better solutions.
>
> IMHO, the --enable-developer was created for adding options like this
> and they should never be on anywhere in default builds.  We should
> remove all warning flags everywhere by default (IMHO, but that's the
> point of a discussion: I could be alone in my thinking).
>
The net-snmp-config has had minor but long-lasting issues for years. It's
one of those things I (as the Debian maintainer) keep coming back and then
do nothing.
Check out --agent-libs, for example:
-Wl,-z,relro -Wl,-z,now -L/usr/lib/x86_64-linux-gnu -lnetsnmpmibs -lsensors
-lpci -lm -lnetsnmpagent -lwrap -Wl,-E -lnetsnmp -lm -lssl -lssl -lssl
-lssl -lcrypto
That could be boiled down to -lnetsnmpmibs -lnetsnmpagent -lnetsnmp, which
is what "pkg-config --libs netsnmp-agent" gives.
No idea why it's got four libssl's

I'm also not sure why net-snmp-config gives you one answer and pkg-config
gives you a different answer.
The standard way most people do is use pkg-config, but perhaps there's
reasons for using the other way?

 - Craig

BTW, 5.9.5.2 has been uploaded for Debian Sid. A patched 5.9.4 is uploaded
but not available yet for Trixie, it's just gurgling through the release
process.

--0000000000009dbc2106470b21e5
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr">On Fri, 26 Dec 2025 at 10:23, Wes Hardake=
r &lt;<a href=3D"mailto:[email protected]">[email protected]=
ceforge.net</a>&gt; wrote:</div><div class=3D"gmail_quote gmail_quote_conta=
iner"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;b=
order-left:1px solid rgb(204,204,204);padding-left:1ex">Bart Van Assche via=
 Net-snmp-coders<br>
&lt;<a href=3D"mailto:[email protected]" target=3D"_bla=
nk">[email protected]</a>&gt; writes:<br>
<br>
&gt; One possible solution is to modify net-snmp-config such that all -W<br=
>
&gt; flags are filtered out. There may be better solutions.<br>
<br>
IMHO, the --enable-developer was created for adding options like this<br>
and they should never be on anywhere in default builds.=C2=A0 We should<br>
remove all warning flags everywhere by default (IMHO, but that&#39;s the<br=
>
point of a discussion: I could be alone in my thinking).<br></blockquote><d=
iv>The net-snmp-config has had minor but long-lasting issues for years. It&=
#39;s one of those things I (as the Debian maintainer) keep coming back and=
 then do nothing.</div><div>Check out --agent-libs, for example:</div><div>=
-Wl,-z,relro -Wl,-z,now -L/usr/lib/x86_64-linux-gnu -lnetsnmpmibs -lsensors=
 -lpci -lm -lnetsnmpagent -lwrap -Wl,-E -lnetsnmp -lm -lssl -lssl -lssl -ls=
sl -lcrypto</div><div>That could be boiled down to -lnetsnmpmibs -lnetsnmpa=
gent -lnetsnmp, which is what &quot;pkg-config --libs netsnmp-agent&quot; g=
ives.</div><div>No idea why=C2=A0it&#39;s got four libssl&#39;s</div><div><=
br></div><div>I&#39;m also not sure why net-snmp-config gives you one answe=
r and pkg-config gives you a different answer.</div><div>The standard way m=
ost people do is use pkg-config, but perhaps there&#39;s reasons for using =
the other way?</div><div><br></div><div>=C2=A0- Craig</div><div><br></div>B=
TW, 5.9.5.2 has been uploaded for Debian Sid. A patched 5.9.4 is uploaded b=
ut not available yet for Trixie, it&#39;s just gurgling through the release=
 process.</div></div>

--0000000000009dbc2106470b21e5--


--===============5999398650220284311==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============5999398650220284311==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Net-snmp-coders mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/net-snmp-coders

--===============5999398650220284311==--