Upstream information

CVE-2014-2284 at MITRE

Description

The Linux implementation of the ICMP-MIB in Net-SNMP 5.5 before 5.5.2.1, 5.6.x before 5.6.2.1, and 5.7.x before 5.7.2.1 does not properly validate input, which allows remote attackers to cause a denial of service via unspecified vectors.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 5
Vector AV:N/AC:L/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
SUSE Bugzilla entries: 866942 [RESOLVED / FIXED], 875217 [NEW]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 11 SP3
  • libsnmp15 >= 5.4.2.1-8.12.20.1
  • libsnmp15-32bit >= 5.4.2.1-8.12.20.1
  • net-snmp >= 5.4.2.1-8.12.20.1
  • perl-SNMP >= 5.4.2.1-8.12.20.1
  • snmp-mibs >= 5.4.2.1-8.12.20.1
Patchnames:
sledsp3-libsnmp15
SUSE Linux Enterprise Desktop 12
  • libsnmp30 >= 5.7.2.1-3.8
  • libsnmp30-32bit >= 5.7.2.1-3.8
  • net-snmp >= 5.7.2.1-3.8
  • perl-SNMP >= 5.7.2.1-3.8
  • snmp-mibs >= 5.7.2.1-3.8
Patchnames:
SUSE Linux Enterprise Desktop 12 GA libsnmp30-32bit
SUSE Linux Enterprise Desktop 12 SP1
  • libsnmp30 >= 5.7.3-4.2
  • libsnmp30-32bit >= 5.7.3-4.2
  • net-snmp >= 5.7.3-4.2
  • perl-SNMP >= 5.7.3-4.2
  • snmp-mibs >= 5.7.3-4.2
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA libsnmp30-32bit
SUSE Linux Enterprise Desktop 12 SP2
  • libsnmp30 >= 5.7.3-4.2
  • libsnmp30-32bit >= 5.7.3-4.2
  • net-snmp >= 5.7.3-4.2
  • perl-SNMP >= 5.7.3-4.2
  • snmp-mibs >= 5.7.3-4.2
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA libsnmp30-32bit
SUSE Linux Enterprise Desktop 12 SP3
  • libsnmp30 >= 5.7.3-4.2
  • libsnmp30-32bit >= 5.7.3-4.2
  • net-snmp >= 5.7.3-4.2
  • perl-SNMP >= 5.7.3-4.2
  • snmp-mibs >= 5.7.3-4.2
Patchnames:
SUSE Linux Enterprise Desktop 12 SP3 GA libsnmp30-32bit
SUSE Linux Enterprise Server 11 SP3
  • libsnmp15 >= 5.4.2.1-8.12.20.1
  • libsnmp15-32bit >= 5.4.2.1-8.12.20.1
  • libsnmp15-x86 >= 5.4.2.1-8.12.22.1
  • net-snmp >= 5.4.2.1-8.12.20.1
  • perl-SNMP >= 5.4.2.1-8.12.20.1
  • snmp-mibs >= 5.4.2.1-8.12.20.1
Patchnames:
slessp3-libsnmp15
SUSE Linux Enterprise Server 11 SP4
  • libsnmp15 >= 5.4.2.1-8.12.22.1
  • libsnmp15-32bit >= 5.4.2.1-8.12.22.1
  • libsnmp15-x86 >= 5.4.2.1-8.12.22.1
  • net-snmp >= 5.4.2.1-8.12.22.1
  • perl-SNMP >= 5.4.2.1-8.12.22.1
  • snmp-mibs >= 5.4.2.1-8.12.22.1
Patchnames:
SUSE Linux Enterprise Server 11 SP4 GA libsnmp15-32bit
SUSE Linux Enterprise Server 12
  • libsnmp30 >= 5.7.2.1-3.8
  • libsnmp30-32bit >= 5.7.2.1-3.8
  • net-snmp >= 5.7.2.1-3.8
  • perl-SNMP >= 5.7.2.1-3.8
  • snmp-mibs >= 5.7.2.1-3.8
Patchnames:
SUSE Linux Enterprise Server 12 GA libsnmp30-32bit
SUSE Linux Enterprise Server 12 SP1
  • libsnmp30 >= 5.7.3-4.2
  • libsnmp30-32bit >= 5.7.3-4.2
  • net-snmp >= 5.7.3-4.2
  • perl-SNMP >= 5.7.3-4.2
  • snmp-mibs >= 5.7.3-4.2
Patchnames:
SUSE Linux Enterprise Server 12 SP1 GA libsnmp30-32bit
SUSE Linux Enterprise Server 12 SP2
  • libsnmp30 >= 5.7.3-4.2
  • libsnmp30-32bit >= 5.7.3-4.2
  • net-snmp >= 5.7.3-4.2
  • perl-SNMP >= 5.7.3-4.2
  • snmp-mibs >= 5.7.3-4.2
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA libsnmp30-32bit
SUSE Linux Enterprise Server 12 SP3
  • libsnmp30 >= 5.7.3-4.2
  • libsnmp30-32bit >= 5.7.3-4.2
  • net-snmp >= 5.7.3-4.2
  • perl-SNMP >= 5.7.3-4.2
  • snmp-mibs >= 5.7.3-4.2
Patchnames:
SUSE Linux Enterprise Server 12 SP3 GA libsnmp30-32bit
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • libsnmp30 >= 5.7.3-4.2
  • net-snmp >= 5.7.3-4.2
  • perl-SNMP >= 5.7.3-4.2
  • snmp-mibs >= 5.7.3-4.2
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA libsnmp30
SUSE Linux Enterprise Server for VMWare 11 SP3
  • libsnmp15 >= 5.4.2.1-8.12.20.1
  • libsnmp15-32bit >= 5.4.2.1-8.12.20.1
  • libsnmp15-x86 >= 5.4.2.1-8.12.22.1
  • net-snmp >= 5.4.2.1-8.12.20.1
  • perl-SNMP >= 5.4.2.1-8.12.20.1
  • snmp-mibs >= 5.4.2.1-8.12.20.1
Patchnames:
slessp3-libsnmp15
SUSE Linux Enterprise Software Development Kit 11 SP3
  • libsnmp15-32bit >= 5.4.2.1-8.12.20.1
  • net-snmp-devel >= 5.4.2.1-8.12.20.1
  • net-snmp-devel-32bit >= 5.4.2.1-8.12.22.1
Patchnames:
sdksp3-libsnmp15
SUSE Linux Enterprise Software Development Kit 11 SP4
  • libsnmp15-32bit >= 5.4.2.1-8.12.22.1
  • net-snmp-devel >= 5.4.2.1-8.12.22.1
  • net-snmp-devel-32bit >= 5.4.2.1-8.12.22.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 11 SP4 GA libsnmp15-32bit
SUSE Linux Enterprise Software Development Kit 12
  • net-snmp-devel >= 5.7.2.1-3.8
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 GA net-snmp-devel
SUSE Linux Enterprise Software Development Kit 12 SP1
  • net-snmp-devel >= 5.7.3-4.2
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP1 GA net-snmp-devel
SUSE Linux Enterprise Software Development Kit 12 SP2
  • net-snmp-devel >= 5.7.3-4.2
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP2 GA net-snmp-devel
SUSE Linux Enterprise Software Development Kit 12 SP3
  • net-snmp-devel >= 5.7.3-4.2
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP3 GA net-snmp-devel
SUSE Linux Enterprise Software Development Kit 11 SP3
  • net-snmp-devel >= 5.4.2.1-8.12.20.1
Builds
SAT Patch Nr: 9015
SUSE Linux Enterprise Software Development Kit 11 SP3
  • net-snmp-devel >= 5.4.2.1-8.12.20.1
  • net-snmp-devel-32bit >= 5.4.2.1-8.12.20.1
Builds
SAT Patch Nr: 9015
SUSE Linux Enterprise Software Development Kit 11 SP3
  • libsnmp15-32bit >= 5.4.2.1-8.12.20.1
  • net-snmp-devel >= 5.4.2.1-8.12.20.1
Builds
SAT Patch Nr: 9015
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP3 for VMware
  • libsnmp15 >= 5.4.2.1-8.12.20.1
  • net-snmp >= 5.4.2.1-8.12.20.1
  • perl-SNMP >= 5.4.2.1-8.12.20.1
  • snmp-mibs >= 5.4.2.1-8.12.20.1
Builds
SAT Patch Nr: 9015
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP3 for VMware
  • libsnmp15 >= 5.4.2.1-8.12.20.1
  • libsnmp15-32bit >= 5.4.2.1-8.12.20.1
  • net-snmp >= 5.4.2.1-8.12.20.1
  • perl-SNMP >= 5.4.2.1-8.12.20.1
  • snmp-mibs >= 5.4.2.1-8.12.20.1
Builds
SAT Patch Nr: 9015
SUSE Linux Enterprise Server 11 SP3
  • libsnmp15 >= 5.4.2.1-8.12.20.1
  • libsnmp15-x86 >= 5.4.2.1-8.12.20.1
  • net-snmp >= 5.4.2.1-8.12.20.1
  • perl-SNMP >= 5.4.2.1-8.12.20.1
  • snmp-mibs >= 5.4.2.1-8.12.20.1
Builds
SAT Patch Nr: 9015
openSUSE 13.1
  • libsnmp30 >= 5.7.2-9.4.1
  • libsnmp30-32bit >= 5.7.2-9.4.1
  • libsnmp30-debuginfo >= 5.7.2-9.4.1
  • libsnmp30-debuginfo-32bit >= 5.7.2-9.4.1
  • net-snmp >= 5.7.2-9.4.1
  • net-snmp-debuginfo >= 5.7.2-9.4.1
  • net-snmp-debugsource >= 5.7.2-9.4.1
  • net-snmp-devel >= 5.7.2-9.4.1
  • net-snmp-devel-32bit >= 5.7.2-9.4.1
  • net-snmp-python >= 5.7.2-9.4.1
  • net-snmp-python-debuginfo >= 5.7.2-9.4.1
  • perl-SNMP >= 5.7.2-9.4.1
  • perl-SNMP-debuginfo >= 5.7.2-9.4.1
  • snmp-mibs >= 5.7.2-9.4.1
Patchnames:
openSUSE-2014-227
openSUSE Leap 42.1
  • libsnmp30 >= 5.7.3-2.5
  • libsnmp30-32bit >= 5.7.3-2.5
  • net-snmp >= 5.7.3-2.5
  • net-snmp-devel >= 5.7.3-2.5
  • perl-SNMP >= 5.7.3-2.5
  • snmp-mibs >= 5.7.3-2.5
Patchnames:
openSUSE Leap 42.1 GA libsnmp30-32bit
openSUSE Leap 42.2
  • libsnmp30 >= 5.7.3-4.5
  • libsnmp30-32bit >= 5.7.3-4.5
  • net-snmp >= 5.7.3-4.5
  • net-snmp-devel >= 5.7.3-4.5
  • perl-SNMP >= 5.7.3-4.5
  • snmp-mibs >= 5.7.3-4.5
Patchnames:
openSUSE Leap 42.2 GA libsnmp30-32bit
openSUSE Leap 42.3
  • libsnmp30 >= 5.7.3-6.6
  • libsnmp30-32bit >= 5.7.3-6.6
  • net-snmp >= 5.7.3-6.6
  • net-snmp-devel >= 5.7.3-6.6
  • perl-SNMP >= 5.7.3-6.6
  • snmp-mibs >= 5.7.3-6.6
Patchnames:
openSUSE Leap 42.3 GA libsnmp30-32bit
openSUSE Tumbleweed
  • libsnmp30 >= 5.7.3-8.4
  • libsnmp30-32bit >= 5.7.3-8.4
  • net-snmp >= 5.7.3-8.4
  • net-snmp-devel >= 5.7.3-8.4
  • net-snmp-devel-32bit >= 5.7.3-8.4
  • net-snmp-python >= 5.7.3-8.4
  • perl-SNMP >= 5.7.3-8.4
  • snmp-mibs >= 5.7.3-8.4
Patchnames:
openSUSE Tumbleweed GA libsnmp30-32bit


Status of this issue by product and package

Product(s) Source package State
SUSE Linux Enterprise Desktop 10 SP3 net-snmp Released
SUSE Linux Enterprise Desktop 10 SP4 net-snmp Released
SUSE Linux Enterprise Desktop 11 SP1 net-snmp Released
SUSE Linux Enterprise Desktop 11 SP3 net-snmp Released
SUSE Linux Enterprise SDK 11 SP1 net-snmp Released
SUSE Linux Enterprise SDK 11 SP3 net-snmp Released
SUSE Linux Enterprise Server 10 SP3 net-snmp Released
SUSE Linux Enterprise Server 10 SP4 net-snmp Released
SUSE Linux Enterprise Server 10 SP4 LTSS net-snmp Released
SUSE Linux Enterprise Server 11 SP1 net-snmp Released
SUSE Linux Enterprise Server 11 SP1 LTSS net-snmp Released
SUSE Linux Enterprise Server 11 SP3 net-snmp Released
SUSE Linux Enterprise Server for SAP AIO 11 SP1 net-snmp Released