Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.871146
Category:Red Hat Local Security Checks
Title:RedHat Update for net-snmp RHSA-2014:0321-01
Summary:The remote host is missing an update for the 'net-snmp'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'net-snmp'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The net-snmp packages provide various libraries and tools for the Simple
Network Management Protocol (SNMP), including an SNMP library, an
extensible agent, tools for requesting or setting information from SNMP
agents, tools for generating and handling SNMP traps, a version of the
netstat command which uses SNMP, and a Tk/Perl Management Information Base
(MIB) browser.

A buffer overflow flaw was found in the way the decode_icmp_msg() function
in the ICMP-MIB implementation processed Internet Control Message Protocol
(ICMP) message statistics reported in the /proc/net/snmp file. A remote
attacker could send a message for each ICMP message type, which could
potentially cause the snmpd service to crash when processing the
/proc/net/snmp file. (CVE-2014-2284)

This update also fixes the following bug:

* The snmpd service parses the /proc/diskstats file to track disk usage
statistics for UCD-DISKIO-MIB::diskIOTable. On systems with a large number
of block devices, /proc/diskstats may be large in size and parsing it can
take a non-trivial amount of CPU time. With this update, Net-SNMP
introduces a new option, 'diskio', in the /etc/snmp/snmpd.conf file, which
can be used to explicitly specify devices that should be monitored.
Only these whitelisted devices are then reported in
UCD-DISKIO-MIB::diskIOTable, thus speeding up snmpd on systems with
numerous block devices. (BZ#990674)

All net-snmp users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the snmpd service will be restarted automatically.

Affected Software/OS:
net-snmp on Red Hat Enterprise Linux Desktop (v. 6),
Red Hat Enterprise Linux Server (v. 6),
Red Hat Enterprise Linux Workstation (v. 6)

Solution:
Please Install the Updated Packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-2284
http://www.gentoo.org/security/en/glsa/glsa-201409-02.xml
http://sourceforge.net/p/net-snmp/code/ci/a1fd64716f6794c55c34d77e618210238a73bfa1/
http://comments.gmane.org/gmane.comp.security.oss.general/12284
RedHat Security Advisories: RHSA-2014:0321
http://rhn.redhat.com/errata/RHSA-2014-0321.html
http://secunia.com/advisories/57124
http://secunia.com/advisories/57526
http://secunia.com/advisories/57583
http://secunia.com/advisories/57870
http://secunia.com/advisories/59974
SuSE Security Announcement: openSUSE-SU-2014:0398 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-03/msg00060.html
SuSE Security Announcement: openSUSE-SU-2014:0399 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-03/msg00061.html
http://www.ubuntu.com/usn/USN-2166-1
CopyrightCopyright (C) 2014 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.