Multiple D-Link Products IP Fragment Reassembly Denial of Service Vulnerability
BID:16621
Info
Multiple D-Link Products IP Fragment Reassembly Denial of Service Vulnerability
| Bugtraq ID: | 16621 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2006 12:00AM |
| Updated: | Feb 14 2006 06:53PM |
| Credit: | Discovered by Aaron Portnoy <[email protected]>. |
| Vulnerable: |
U.S.Robotics USR8054 0 D-Link DI-784 0 D-Link DI-624 0 D-Link DI-524 3.20 D-Link DI-524 0 |
| Not Vulnerable: |
D-Link DI-614+ 2.30 D-Link DI-614+ 2.18 D-Link DI-614+ 2.10 D-Link DI-614+ 2.0 f D-Link DI-614+ 2.0 3g D-Link DI-614+ 2.0 3 D-Link DI-614+ 2.0 D-Link DI-604 |
Discussion
Multiple D-Link Products IP Fragment Reassembly Denial of Service Vulnerability
Multiple D-Link devices are susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected devices that causes them to fail when attempting to reassemble certain IP packets.
This issue allows remote attackers to crash and reboot affected devices, denying service to legitimate users.
D-Link DI-524, DI-624, and Di-784 devices are affected by this issue. Due to code reuse among routers, other devices may also be affected.
It is reported that US Robotics USR8054 devices are also affected.
Multiple D-Link devices are susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected devices that causes them to fail when attempting to reassemble certain IP packets.
This issue allows remote attackers to crash and reboot affected devices, denying service to legitimate users.
D-Link DI-524, DI-624, and Di-784 devices are affected by this issue. Due to code reuse among routers, other devices may also be affected.
It is reported that US Robotics USR8054 devices are also affected.
Exploit / POC
Multiple D-Link Products IP Fragment Reassembly Denial of Service Vulnerability
An exploit is not required.
An exploit by Aaron Portnoy is available that is designed to send packets that trigger this issue.
An exploit is not required.
An exploit by Aaron Portnoy is available that is designed to send packets that trigger this issue.
Solution / Fix
Multiple D-Link Products IP Fragment Reassembly Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Multiple D-Link Products IP Fragment Reassembly Denial of Service Vulnerability
References:
References:
- D-Link Fragmented UDP Denial of Service Vulnerability (Aaron Portnoy)
- U.S.Robotics Homepage (U.S.Robotics)
- Vendor Homepage (D-Link)