CVE-2014-3565 PUBLISHED

snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB file, as demonstrated by a NULL type in an ifMtu trap message.

EPSS 8.76% · 92.4th percentile

Risk Scores

EPSS Score
8.76%
92.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSnet-snmp0, 5.7.2~dfsg-8ubuntu1, 5.7.2~dfsg-8ubuntu2

Timeline

References

Open in Interactive Console →