SB2014032508 - Amazon Linux AMI update for net-snmp
Published: March 25, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Resource management error (CVE-ID: CVE-2012-6151)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of service (crash or infinite loop, CPU consumption, and hang) by causing the AgentX subagent to timeout.
2) Input validation error (CVE-ID: CVE-2014-2284)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The Linux implementation of the ICMP-MIB in Net-SNMP 5.5 before 5.5.2.1, 5.6.x before 5.6.2.1, and 5.7.x before 5.7.2.1 does not properly validate input, which allows remote attackers to cause a denial of service via unspecified vectors.
Remediation
Install update from vendor's website.