CVE-2014-2285
published 2014-04-27CVE-2014-2285: The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.31%
87.2th percentile
The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | net-snmp | < net-snmp 5.7.2.1~dfsg-3 (bookworm) | net-snmp 5.7.2.1~dfsg-3 (bookworm) |
| net-snmp | net-snmp | <= 5.7.3 | — |
| net-snmp | net-snmp | >= 0 < 5.7.2.1~dfsg-3 | 5.7.2.1~dfsg-3 |
| net-snmp | net-snmp | >= 0 < 5.7.2.1~dfsg-3 | 5.7.2.1~dfsg-3 |
| net-snmp | net-snmp | >= 0 < 5.7.2.1~dfsg-3 | 5.7.2.1~dfsg-3 |
| net-snmp | net-snmp | >= 0 < 5.7.2.1~dfsg-3 | 5.7.2.1~dfsg-3 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
net-snmp 5.7.3 PERL newSVpv Community String input validation (Nessus ID 73163 / ID 123075)
vuldb·2026-05-12·CVSS 4.3
CVE-2014-2285 [MEDIUM] net-snmp 5.7.3 PERL newSVpv Community String input validation (Nessus ID 73163 / ID 123075)
A vulnerability was found in net-snmp 5.7.3. It has been classified as problematic. This vulnerability affects the function newSVpv of the component PERL Handler. The manipulation as part of Community String leads to improper input validation.
This vulnerability is documented as CVE-2014-2285. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-vjgw-84x2-wchq: The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver
ghsa_unreviewed·2022-05-17
CVE-2014-2285 [MEDIUM] CWE-20 GHSA-vjgw-84x2-wchq: The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver
The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.
OSV
CVE-2014-2285: The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver
osv·2014-04-27·CVSS 4.3
CVE-2014-2285 [MEDIUM] CVE-2014-2285: The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver
The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.
Ubuntu
Net-SNMP vulnerabilities
vendor_ubuntu·2014-04-14·CVSS 4.3
CVE-2012-6151 [MEDIUM] Net-SNMP vulnerabilities
Title: Net-SNMP vulnerabilities
Summary: Net-SNMP could be made to crash if it received specially crafted network
traffic.
Ken Farnen discovered that Net-SNMP incorrectly handled AgentX timeouts. A
remote attacker could use this issue to cause the server to crash or to
hang, resulting in a denial of service. (CVE-2012-6151)
It was discovered that the Net-SNMP ICMP-MIB incorrectly validated input. A
remote attacker could use this issue to cause the server to crash,
resulting in a denial of service. This issue only affected Ubuntu 13.10.
(CVE-2014-2284)
Viliam Púčik discovered that the Net-SNMP perl trap handler incorrectly
handled NULL arguments. A remote attacker could use this issue to cause the
server to crash, resulting in a denial of service. (CVE-2014-2285)
It was discovered that
Red Hat
net-snmp: snmptrapd crash when using a trap with empty community string
vendor_redhat·2014-03-03·CVSS 4.3
CVE-2014-2285 [MEDIUM] net-snmp: snmptrapd crash when using a trap with empty community string
net-snmp: snmptrapd crash when using a trap with empty community string
The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.
Statement: This issue did not affect the versions of net-snmp as shipped with Red Hat Enterprise Linux 6.
Package: net-snmp (Red Hat Enterprise Linux 6) - Not affected
Package: net-snmp (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-2285: net-snmp - The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP...
vendor_debian·2014·CVSS 4.3
CVE-2014-2285 [MEDIUM] CVE-2014-2285: net-snmp - The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP...
The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.
Scope: local
bookworm: resolved (fixed in 5.7.2.1~dfsg-3)
bullseye: resolved (fixed in 5.7.2.1~dfsg-3)
forky: resolved (fixed in 5.7.2.1~dfsg-3)
sid: resolved (fixed in 5.7.2.1~dfsg-3)
trixie: resolved (fixed in 5.7.2.1~dfsg-3)
No detection rules found.
No public exploits indexed.
http://comments.gmane.org/gmane.comp.security.oss.general/12284http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.opensuse.org/opensuse-updates/2014-03/msg00060.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00061.htmlhttp://secunia.com/advisories/59974http://sourceforge.net/p/net-snmp/patches/1275/http://www.gentoo.org/security/en/glsa/glsa-201409-02.xmlhttp://www.nntp.perl.org/group/perl.perl5.porters/2006/09/msg116250.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1072044https://bugzilla.redhat.com/show_bug.cgi?id=1072778https://rhn.redhat.com/errata/RHSA-2014-0322.htmlhttp://comments.gmane.org/gmane.comp.security.oss.general/12284http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.opensuse.org/opensuse-updates/2014-03/msg00060.htmlhttp://lists.opensuse.org/opensuse-updates/2014-03/msg00061.htmlhttp://secunia.com/advisories/59974http://sourceforge.net/p/net-snmp/patches/1275/http://www.gentoo.org/security/en/glsa/glsa-201409-02.xmlhttp://www.nntp.perl.org/group/perl.perl5.porters/2006/09/msg116250.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1072044https://bugzilla.redhat.com/show_bug.cgi?id=1072778https://rhn.redhat.com/errata/RHSA-2014-0322.html
2014-04-27
Published