Denial of Service Vulnerability in Net-SNMP by The Net-SNMP Project
CVE-2014-2285

Currently unrated

Key Information:

Vendor

Net-snmp

Status
Vendor
CVE Published:
27 April 2014

What is CVE-2014-2285?

The perl_trapd_handler function in Net-SNMP versions prior to 5.7.3.pre3 contains a vulnerability that can be exploited by remote attackers. By sending an SNMP trap with an empty community string, an attacker can trigger a NULL pointer dereference in the newSVpv function within Perl, leading to a crash of the snmptrapd process. This flaw underscores the need for strict validation of input parameters to avoid unintended service disruptions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.