MGASA-2014-0122
Dashboard / Vulnerabilities / MGASA-2014-0122
Summary: Updated net-snmp packages fix two vulnerabilities
Details: Updated net-snmp packages fix security vulnerabilities: Remotely exploitable denial of service vulnerability in Net-SNMP, in the Linux implementation of the ICMP-MIB, making the SNMP agent vulnerable if it is making use of the ICMP-MIB table objects (CVE-2014-2284). Remotely exploitable denial of service vulnerability in Net-SNMP, in snmptrapd, due to how it handles trap requests with an empty community string when the perl handler is enabled (CVE-2014-2285).
References: https://advisories.mageia.org/MGASA-2014-0122.html, http://freecode.com/projects/net-snmp/releases/361848, http://openwall.com/lists/oss-security/2014/03/05/9, https://bugzilla.redhat.com/show_bug.cgi?id=1070396, https://bugzilla.redhat.com/show_bug.cgi?id=1072778, https://bugs.mageia.org/show_bug.cgi?id=12880
Affected packages
Package
Name: net-snmp
Purl: pkg:rpm/mageia/net-snmp?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
