CVE-2014-2285 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2285): The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an empty community string in an SNMP trap, which triggers a NULL pointer dereference within the newSVpv function in Perl.
Arch teams, please test and mark stable: =net-analyzer/net-snmp-5.7.3_pre3 Targeted stable KEYWORDS : alpha amd64 arm hppa ia64 ppc ppc64 sparc x86
amd64 stable
x86 stable
Stable for HPPA.
arm stable
ppc stable
ppc64 stable
ia64 stable
sparc stable
alpha stable. Maintainer(s), please cleanup. Security, please vote.
Arches and Maintainer(s), Thank you for your work! Security please Vote!
Adding to existing GLSA draft.
This issue was resolved and addressed in GLSA 201409-02 at http://security.gentoo.org/glsa/glsa-201409-02.xml by GLSA coordinator Kristian Fiskerstrand (K_F).