Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu: 2166-1 Critical: Net-SNMP Service Interruption Vulnerabilities

ubuntu
Calendar Grey April 14, 2014
Scroller Ubuntu
Ubuntu 13.10 and earlier releases affected by Net-SNMP security flaws leading to system instability and service interruptions, please update immediately.
Net-SNMP could be made to crash if it received specially crafted network traffic.

Summary

Net-SNMP could be made to crash if it received specially crafted network

traffic.

Software Description:

- net-snmp: SNMP (Simple Network Management Protocol) server and applications

Details:

Ken Farnen discovered that Net-SNMP incorrectly handled AgentX timeouts. A

remote attacker could use this issue to cause the server to crash or to

hang, resulting in a denial of service. (CVE-2012-6151)

It was discovered that the Net-SNMP ICMP-MIB incorrectly validated input. A

remote attacker could use this issue to cause the server to crash,

resulting in a denial of service. This issue only affected Ubuntu 13.10.

(CVE-2014-2284)

Viliam Púčik discovered that the Net-SNMP perl trap handler incorrectly

handled NULL arguments. A remote attacker could use this issue to cause the

server to crash, resulting in a denial of service. (CVE-2014-2285)

It was discovered that Net-SNMP incorrectly handled AgentX multi-object

requests. A remote attacker could use this issue to ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  libsnmp30                       5.7.2~dfsg-8ubuntu1.1

Ubuntu 12.10:
  libsnmp15                       5.4.3~dfsg-2.5ubuntu1.1

Ubuntu 12.04 LTS:
  libsnmp15                       5.4.3~dfsg-2.4ubuntu1.2

Ubuntu 10.04 LTS:
  libsnmp15                       5.4.2.1~dfsg0ubuntu1-0ubuntu2.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2166-1

CVE-2012-6151, CVE-2014-2284, CVE-2014-2285, CVE-2014-2310

Severity
critical
Lowest
Low
Medium
High
Critical

April 14, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.