Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-2285

Опубликовано: 03 мар. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.

Отчет

This issue did not affect the versions of net-snmp as shipped with Red Hat Enterprise Linux 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6net-snmpNot affected
Red Hat Enterprise Linux 7net-snmpNot affected
Red Hat Enterprise Linux 5net-snmpFixedRHSA-2014:032224.03.2014

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1072778net-snmp: snmptrapd crash when using a trap with empty community string

EPSS

Процентиль: 86%
0.03115
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.

nvd
больше 11 лет назад

The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.

debian
больше 11 лет назад

The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs i ...

github
больше 3 лет назад

The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.

oracle-oval
больше 11 лет назад

ELSA-2014-0322: net-snmp security update (MODERATE)

EPSS

Процентиль: 86%
0.03115
Низкий

4.3 Medium

CVSS2