MGASA-2014-0122

Source
https://advisories.mageia.org/MGASA-2014-0122.html
Import Source
https://advisories.mageia.org/MGASA-2014-0122.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0122
Related
Published
2014-03-07T14:16:46Z
Modified
2014-03-07T14:16:38Z
Summary
Updated net-snmp packages fix two vulnerabilities
Details

Updated net-snmp packages fix security vulnerabilities:

Remotely exploitable denial of service vulnerability in Net-SNMP, in the Linux implementation of the ICMP-MIB, making the SNMP agent vulnerable if it is making use of the ICMP-MIB table objects (CVE-2014-2284).

Remotely exploitable denial of service vulnerability in Net-SNMP, in snmptrapd, due to how it handles trap requests with an empty community string when the perl handler is enabled (CVE-2014-2285).

References
Credits

Affected packages

Mageia:3 / net-snmp

Package

Name
net-snmp
Purl
pkg:rpm/mageia/net-snmp?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.7.2-7.2.mga3

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / net-snmp

Package

Name
net-snmp
Purl
pkg:rpm/mageia/net-snmp?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.7.2-13.1.mga4

Ecosystem specific

{
    "section": "core"
}