First published: Thu Jul 31 2014(Updated: )
A remote denial-of-service flaw was found in the way snmptrapd handled certain SNMP traps when started with the "-OQ" option. If an attacker sent an SNMP trap containing a variable with a NULL type where an integer variable type was expected, it would cause snmptrapd to crash.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.11.0 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =15.04 | |
Net-SNMP | <=5.7.0 | |
Net-SNMP | =5.0 | |
Net-SNMP | =5.0.1 | |
Net-SNMP | =5.0.2 | |
Net-SNMP | =5.0.3 | |
Net-SNMP | =5.0.4 | |
Net-SNMP | =5.0.5 | |
Net-SNMP | =5.0.6 | |
Net-SNMP | =5.0.7 | |
Net-SNMP | =5.0.8 | |
Net-SNMP | =5.0.9 | |
Net-SNMP | =5.1 | |
Net-SNMP | =5.1.2 | |
Net-SNMP | =5.2 | |
Net-SNMP | =5.3 | |
Net-SNMP | =5.3.0.1 | |
Net-SNMP | =5.4 | |
Net-SNMP | =5.5 | |
Net-SNMP | =5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3565 is classified as a remote denial-of-service vulnerability.
To fix CVE-2014-3565, update the affected software to a version that has patched this vulnerability.
CVE-2014-3565 affects various versions of Net-SNMP and specific versions of macOS and Ubuntu.
If exploited, CVE-2014-3565 can cause the snmptrapd service to crash, leading to a denial of service.
A temporary workaround for CVE-2014-3565 might be to avoid using the "-OQ" option with snmptrapd until patched.