How secure i snmp?
Not very and it's never been. V1 and V2 of the protocol lack all but the most basic forms of access control. They are easily spoofed and don't use a reliable transport mechanism, even though SNMP traps could be and are used to warn of critical events. SNMP traffic is also entirely in the clear. SNMPv3 introduces better authentication. Bottom line is that SNMP is very useful for network management, but you should think twice (at least) before employing it in or across an untrusted network.
I wanna use it for some graphocal stats (CPU, MEM, etc..), so i have to use it.
Use a dedicated trusted network or use IPSec or similar techniques to protect SNMP.
I have read that u can crash snmp, but i haven found a root exploit or something like that. If it u can just crash it, then it´s not a big security deal, is it?
Quoting from the CERT advisory: "...may result in denial-of-service conditions, format string vulnerabilities, and buffer overflows." Sounds like a root exploit is 'left as an exercise to the reader'. Note that many bugs that result in crashes of the associated program are buffer overflows. Tobias