Multiple D-Link Routers UPNP Buffer Overflow Vulnerability
BID:19006
CVE-2006-3687 |Info
Multiple D-Link Routers UPNP Buffer Overflow Vulnerability
| Bugtraq ID: | 19006 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2006 12:00AM |
| Updated: | Jul 24 2006 06:02PM |
| Credit: | Barnaby Jack is credited with discovering this vulnerability. |
| Vulnerable: |
D-Link WBR-2310 Rev A D-Link WBR-1310 Rev A D-Link EBR-2310 Rev A D-Link DI-784 Rev A D-Link DI-624 Rev D D-Link DI-624 Rev C D-Link DI-604 Rev E D-Link DI-524 Rev D D-Link DI-524 Rev C D-Link DI-524 Rev B2 D-Link DI-524 Rev B1 D-Link DI-524 Rev A |
| Not Vulnerable: | |
Discussion
Multiple D-Link Routers UPNP Buffer Overflow Vulnerability
D-Link wired and wireless routers are prone to a buffer-overflow vulnerability because these devices fail to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successful exploits can allow remote attackers to execute arbitrary machine code in the context of the affected device.
D-Link wired and wireless routers are prone to a buffer-overflow vulnerability because these devices fail to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Successful exploits can allow remote attackers to execute arbitrary machine code in the context of the affected device.
Exploit / POC
Multiple D-Link Routers UPNP Buffer Overflow Vulnerability
Attackers can exploit this issue by sending a request of the form:
M-SEARCH <800 byte string> HTTP/1.0
to UDP port 1900.
Attackers can exploit this issue by sending a request of the form:
M-SEARCH <800 byte string> HTTP/1.0
to UDP port 1900.
Solution / Fix
Multiple D-Link Routers UPNP Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected]:[email protected].
Reports indicate that the vendor may have fixes to address this issue. Please contact the vendor for more information.
Solution:
Currently, we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected]:[email protected].
Reports indicate that the vendor may have fixes to address this issue. Please contact the vendor for more information.
References
Multiple D-Link Routers UPNP Buffer Overflow Vulnerability
References:
References:
- D-Link Homepage (D-Link)
- eEye Advisories (eEye Digital Security)
- [EEYEB-20060227] D-Link Router UPNP Stack Overflow (eEye Digital Security)
- RE: [EEYEB-20060227] D-Link Router UPNP Stack Overflow ("m"
)