Linksys SPA921 VoIP Phone HTTP Server Denial Of Service Vulnerabilities
BID:20346
Info
Linksys SPA921 VoIP Phone HTTP Server Denial Of Service Vulnerabilities
| Bugtraq ID: | 20346 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-7121 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 04 2006 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | Shawn Merdinger discovered this issue. |
| Vulnerable: |
Linksys SPA921 VoIP Phone 0 |
| Not Vulnerable: | |
Discussion
Linksys SPA921 VoIP Phone HTTP Server Denial Of Service Vulnerabilities
Linksys SPA921 VoIP phones are prone to denial-of-service vulnerabilities because the devices fail to properly handle large user-supplied input values in HTTP traffic.
Exploiting this issue allows remote attackers to crash and reboot affected devices, denying service to legitimate users.
Linksys SPA921 VoIP phones are prone to denial-of-service vulnerabilities because the devices fail to properly handle large user-supplied input values in HTTP traffic.
Exploiting this issue allows remote attackers to crash and reboot affected devices, denying service to legitimate users.
Exploit / POC
Linksys SPA921 VoIP Phone HTTP Server Denial Of Service Vulnerabilities
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Linksys SPA921 VoIP Phone HTTP Server Denial Of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Linksys SPA921 VoIP Phone HTTP Server Denial Of Service Vulnerabilities
References:
References:
- SPA921 Product Page (Linksys)