PT-2014-1816 · Net Snmp+2 · Net-Snmp+2
Publicado
2014-03-07
·
Atualizado
2024-06-15
·
CVE-2014-2285
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Net-SNMP versions 5.3.2.2 through 5.7.3.pre3
Net-SNMP version 5.3.2.2
Description
The issue concerns multiple vulnerabilities in the Net-SNMP package, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. The perl trapd handler function in certain Perl versions allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, triggering a NULL pointer dereference within the newSVpv function in Perl.
Recommendations
For Net-SNMP versions 5.3.2.2, consider disabling the perl trapd handler function as a temporary workaround until a patch is available.
For Net-SNMP versions 5.3.2.2, restrict access to the SNMP trap endpoint to minimize the risk of exploitation.
For Net-SNMP versions prior to 5.7.3.pre3, update to a newer version to mitigate the risk.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for some versions, so consider general security best practices to minimize potential risks.
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Net-Snmp
Red Hat
Suse