Mandriva Linux Security Advisory : net-snmp (MDVSA-2015:092)
Medium Nessus Plugin ID 82345
SynopsisThe remote Mandriva Linux host is missing one or more security updates.
DescriptionUpdated net-snmp packages fix security vulnerabilities :
Remotely exploitable denial of service vulnerability in Net-SNMP, in the Linux implementation of the ICMP-MIB, making the SNMP agent vulnerable if it is making use of the ICMP-MIB table objects (CVE-2014-2284).
Remotely exploitable denial of service vulnerability in Net-SNMP, in snmptrapd, due to how it handles trap requests with an empty community string when the perl handler is enabled (CVE-2014-2285).
A remote denial-of-service flaw was found in the way snmptrapd handled certain SNMP traps when started with the -OQ option. If an attacker sent an SNMP trap containing a variable with a NULL type where an integer variable type was expected, it would cause snmptrapd to crash (CVE-2014-3565).
SolutionUpdate the affected packages.