Release date:
Updated on:
Affected Systems:
Net-SNMP net-snmp
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65968
CVE (CAN) ID: CVE-2014-2285
Net-SNMP is a free, open-source SNMP implementation, formerly called UCD-SNMP.
Net-snmp-perl 5.3.2.2 and other versions crash when handling empty community strings. Remote attackers can exploit this vulnerability to cause the Net-SNMP Perl processor process to crash and cause DOS.
<* Source: vendor
Link: http://seclists.org/oss-sec/2014/q1/506
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Net-SNMP
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://sourceforge.net/projects/net-snmp/
Net-SNMP details: click here
Net-SNMP: click here
Install Net-SNMP in RPM mode in Linux
Use of Net-SNMPv3 in openSUSE 11.2
Net-SNMP mib2c Configuration
Install Net-SNMP in Ubuntu
Ubuntu installation Net-SNMP-5.5.1 method summary