Pingtel Xpressa Handset Remote Denial Of Service Vulnerability
BID:11161
Info
Pingtel Xpressa Handset Remote Denial Of Service Vulnerability
| Bugtraq ID: | 11161 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2004 12:00AM |
| Updated: | Sep 13 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to @stake, Inc. |
| Vulnerable: |
Pingtel Xpressa 2.1.11 .24 Pingtel Xpressa 2.0.1 Pingtel Xpressa 2.0 Pingtel Xpressa 1.2.8 Pingtel Xpressa 1.2.7 .4 Pingtel Xpressa 1.2.5 |
| Not Vulnerable: | |
Discussion
Pingtel Xpressa Handset Remote Denial Of Service Vulnerability
Pingtel Xpressa handsets are reported prone to a remote denial of service vulnerability. The issue is reported to exist because of a lack of sufficient boundary checks performed on HTTP request data handled by the Xpressa administration web server.
It is reported that a remote attacker may exploit this vulnerability to effectively deny service to the affected handset. Due to the nature of this vulnerability, it is reported that this issue may be exploited in order to execute arbitrary code.
Pingtel Xpressa handsets are reported prone to a remote denial of service vulnerability. The issue is reported to exist because of a lack of sufficient boundary checks performed on HTTP request data handled by the Xpressa administration web server.
It is reported that a remote attacker may exploit this vulnerability to effectively deny service to the affected handset. Due to the nature of this vulnerability, it is reported that this issue may be exploited in order to execute arbitrary code.
Exploit / POC
Pingtel Xpressa Handset Remote Denial Of Service Vulnerability
The following proof of concept is available:
GET /<buffer>/cgi/application.cgi HTTP/1.0
Authorization: Basic [base64authstring]
The following proof of concept is available:
GET /<buffer>/cgi/application.cgi HTTP/1.0
Authorization: Basic [base64authstring]
Solution / Fix
Pingtel Xpressa Handset Remote Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Pingtel Xpressa Handset Remote Denial Of Service Vulnerability
References:
References:
- Pingtel Homepage (Pingtel)
- Pingtel Xpressa Denial of Service (@stake)
- @stake advisory: Pingtel Xpressa Denial of Service ("Advisories"
)