SUSE Security Announcement – The net-snmp daemon implements the “simple network management protocol”. The version 3 of SNMP as implemented in net-snmp uses the length of the HMAC in a packet to verify against a local HMAC for authentication. An attacker can therefore send a SNMPv3 packet with a one byte HMAC and guess the correct first byte of the local HMAC with 256 packets (max).
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/68741/SUSE-SA-2008-039.txt
Source: https://packetstormsecurity.com/files/68741/SUSE-SA-2008-039.txt.html

