CVE-2014-2284: Input Validation
Published Mar 24, 2014
·Updated
The Linux implementation of the ICMP-MIB in Net-SNMP 5.5 before 5.5.2.1, 5.6.x before 5.6.2.1, and 5.7.x before 5.7.2.1 does not properly validate input, which allows remote attackers to cause a denial of service via unspecified vectors.
Affected Software
12 affected components
Net-SNMP Net-SNMP=5.5
Net-SNMP Net-SNMP=5.5.0.1
Net-SNMP Net-SNMP=5.5.0.2
Net-SNMP Net-SNMP=5.5.1
Net-SNMP Net-SNMP=5.5.1.1
Net-SNMP Net-SNMP=5.5.2
Net-SNMP Net-SNMP=5.6
Net-SNMP Net-SNMP=5.6.1.1
Net-SNMP Net-SNMP=5.6.2
Net-SNMP Net-SNMP=5.7
Net-SNMP Net-SNMP=5.7.1
Net-SNMP Net-SNMP=5.7.2
Event History
Mar 24, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·04:43 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2284?
CVE-2014-2284 has a severity rating that allows remote attackers to cause a denial of service.
2
How do I fix CVE-2014-2284?
To fix CVE-2014-2284, upgrade to Net-SNMP version 5.5.2.1 or later, 5.6.2.1 or later, or 5.7.2.1 or later.
3
Which versions of Net-SNMP are affected by CVE-2014-2284?
Versions of Net-SNMP affected by CVE-2014-2284 include 5.5, 5.6.x before 5.6.2.1, and 5.7.x before 5.7.2.1.
4
Can CVE-2014-2284 be exploited remotely?
Yes, CVE-2014-2284 can be exploited remotely by attackers through unspecified vectors.
5
What type of vulnerability is CVE-2014-2284 categorized as?
CVE-2014-2284 is categorized as a denial of service vulnerability affecting the ICMP-MIB implementation in Net-SNMP.