CVE-2014-2285

The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.
Configurations

Configuration 1 (hide)

cpe:2.3:a:net-snmp:net-snmp:*:pre1:*:*:*:*:*:*

History

21 Nov 2024, 02:06

Type Values Removed Values Added
References () http://comments.gmane.org/gmane.comp.security.oss.general/12284 - () http://comments.gmane.org/gmane.comp.security.oss.general/12284 -
References () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 - () http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 -
References () http://lists.opensuse.org/opensuse-updates/2014-03/msg00060.html - () http://lists.opensuse.org/opensuse-updates/2014-03/msg00060.html -
References () http://lists.opensuse.org/opensuse-updates/2014-03/msg00061.html - () http://lists.opensuse.org/opensuse-updates/2014-03/msg00061.html -
References () http://secunia.com/advisories/59974 - () http://secunia.com/advisories/59974 -
References () http://sourceforge.net/p/net-snmp/patches/1275/ - () http://sourceforge.net/p/net-snmp/patches/1275/ -
References () http://www.gentoo.org/security/en/glsa/glsa-201409-02.xml - () http://www.gentoo.org/security/en/glsa/glsa-201409-02.xml -
References () http://www.nntp.perl.org/group/perl.perl5.porters/2006/09/msg116250.html - () http://www.nntp.perl.org/group/perl.perl5.porters/2006/09/msg116250.html -
References () https://bugzilla.redhat.com/show_bug.cgi?id=1072044 - Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1072044 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=1072778 - () https://bugzilla.redhat.com/show_bug.cgi?id=1072778 -
References () https://rhn.redhat.com/errata/RHSA-2014-0322.html - () https://rhn.redhat.com/errata/RHSA-2014-0322.html -

Information

Published : 2014-04-27 22:55

Updated : 2024-11-21 02:06


NVD link : CVE-2014-2285

Mitre link : CVE-2014-2285

CVE.ORG link : CVE-2014-2285


JSON object : View

Products Affected

net-snmp

  • net-snmp
CWE
CWE-20

Improper Input Validation