PT-2014-1816 · Net Snmp+2 · Net-Snmp+2

Published

2014-03-07

·

Updated

2024-06-15

·

CVE-2014-2285

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Net-SNMP versions 5.3.2.2 through 5.7.3.pre3 Net-SNMP version 5.3.2.2
Description The issue concerns multiple vulnerabilities in the Net-SNMP package, which can lead to a disruption of protected information availability. These vulnerabilities can be exploited remotely. The perl trapd handler function in certain Perl versions allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, triggering a NULL pointer dereference within the newSVpv function in Perl.
Recommendations For Net-SNMP versions 5.3.2.2, consider disabling the perl trapd handler function as a temporary workaround until a patch is available. For Net-SNMP versions 5.3.2.2, restrict access to the SNMP trap endpoint to minimize the risk of exploitation. For Net-SNMP versions prior to 5.7.3.pre3, update to a newer version to mitigate the risk. At the moment, there is no information about a newer version that contains a fix for this vulnerability for some versions, so consider general security best practices to minimize potential risks.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06117
BDU:2015-06118
BDU:2015-06119
BDU:2015-06120
BDU:2015-06121
BDU:2015-08933
BDU:2015-08934
BDU:2015-08935
BDU:2015-08936
BDU:2015-08937
CVE-2014-2285
MGASA-2014-0122
OPENSUSE-SU-2024:10204-1
RHSA-2014:0322
RHSA-2014_0322

Affected Products

Net-Snmp
Red Hat
Suse