http://www.mandriva.com/en/
______________________________
Package : net-snmp
Date : March 28, 2015
Affected: Business Server 2.0
______________________________
Problem Description:
Updated net-snmp packages fix security vulnerabilities:
Remotely exploitable denial of service vulnerability in Net-SNMP,
in the Linux implementation of the ICMP-MIB, making the SNMP
agent vulnerable if it is making use of the ICMP-MIB table objects
(CVE-2014-2284).
Remotely exploitable denial of service vulnerability in Net-SNMP,
in snmptrapd, due to how it handles trap requests with an empty
community string when the perl handler is enabled (CVE-2014-2285).
A remote denial-of-service flaw was found in the way snmptrapd handled
certain SNMP traps when started with the -OQ option. If an attacker
sent an SNMP trap containing a variable with a NULL type where an
integer variable type was expected, it would cause snmptrapd to crash
(CVE-2014-3565).
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://advisories.mageia.org/
http://advisories.mageia.org/
______________________________
Updated Packages:
Mandriva Business Server 2/X86_64:
db108bc819bb011d352ac1be23005a
10d0754baaebe770c0accea30a4c57
f3c20caeb88eee898508110847de93
85a8e55a06278248c6d55ed71781d4
dd6b3752ffc3abfa799752d6c68be2
dff402077edcdbbbb43876ab37f17c
e5dd0695599ce24250e9c56398ae70
73e35840936e48e76813ee9aa563e5
3fcb54fc22046478a1f4fe25bfb3fb
f7faf7abe0cb4119a24aa1eb7b4e88
70325be4b29a38030ee30a1bea4c0a
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą