Ubuntu 10.04 LTS / 12.04 LTS / 12.10 / 13.10 : net-snmp vulnerabilities (USN-2166-1)

Ubuntu Security Notice (C) 2014-2016 Canonical, Inc. / NASL script (C) 2014-2016 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing one or more security-related
patches.

Description :

Ken Farnen discovered that Net-SNMP incorrectly handled AgentX
timeouts. A remote attacker could use this issue to cause the server
to crash or to hang, resulting in a denial of service. (CVE-2012-6151)

It was discovered that the Net-SNMP ICMP-MIB incorrectly validated
input. A remote attacker could use this issue to cause the server to
crash, resulting in a denial of service. This issue only affected
Ubuntu 13.10. (CVE-2014-2284)

Viliam Pucik discovered that the Net-SNMP perl trap handler
incorrectly handled NULL arguments. A remote attacker could use this
issue to cause the server to crash, resulting in a denial of service.
(CVE-2014-2285)

It was discovered that Net-SNMP incorrectly handled AgentX
multi-object requests. A remote attacker could use this issue to cause
the server to hang, resulting in a denial of service. This issue only
affected Ubuntu 10.04 LTS, Ubuntu 12.04 LTS and Ubuntu 12.10.
(CVE-2014-2310).

Note that Tenable Network Security has extracted the preceding
description block directly from the Ubuntu security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

Solution :

Update the affected libsnmp15 and / or libsnmp30 packages.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 4.3
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 73513 ()

Bugtraq ID: 64048
65867
65968
66005

CVE ID: CVE-2012-6151
CVE-2014-2284
CVE-2014-2285
CVE-2014-2310

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial