CVE-2014-2284Improper Input Validation in Net-snmp

Severity
5.0MEDIUMNVD
EPSS
4.1%
top 11.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 24
Latest updateMay 17

Description

The Linux implementation of the ICMP-MIB in Net-SNMP 5.5 before 5.5.2.1, 5.6.x before 5.6.2.1, and 5.7.x before 5.7.2.1 does not properly validate input, which allows remote attackers to cause a denial of service via unspecified vectors.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/net-snmp< net-snmp 5.7.2.1~dfsg-3 (bookworm)
Debiannet-snmp/net-snmp< 5.7.2.1~dfsg-3+3
NVDnet-snmp/net-snmp12 versions+11

🔴Vulnerability Details

2
GHSA
GHSA-87fv-phj9-vf23: The Linux implementation of the ICMP-MIB in Net-SNMP 52022-05-17
OSV
CVE-2014-2284: The Linux implementation of the ICMP-MIB in Net-SNMP 52014-03-24

📋Vendor Advisories

3
Ubuntu
Net-SNMP vulnerabilities2014-04-14
Red Hat
net-snmp: denial of service flaw in Linux implementation of ICMP-MIB2014-02-25
Debian
CVE-2014-2284: net-snmp - The Linux implementation of the ICMP-MIB in Net-SNMP 5.5 before 5.5.2.1, 5.6.x b...2014

💬Community

1
Bugzilla
CVE-2014-2284 net-snmp: denial of service flaw in Linux implementation of ICMP-MIB2014-02-26