Hughes Technologies DSL_Vdns Denial of Service Vulnerability
BID:2700
Info
Hughes Technologies DSL_Vdns Denial of Service Vulnerability
| Bugtraq ID: | 2700 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-0580 |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Discovered and posted to Bugtraq by <[email protected]> on May 7, 2001. |
| Vulnerable: |
Hughes Technologies DSL_Vdns 1.0 |
| Not Vulnerable: |
Hughes Technologies DSL_Vdns 2.0 |
Discussion
Hughes Technologies DSL_Vdns Denial of Service Vulnerability
It is possible for a remote user to cause a denial of service on a host running DSL_Vdns. Submitting data to port 6070 and closing the connection before the request is fulfilled, will cause DSL_Vdns to enter a 'Default.Closed' state; therefore, refusing any new connections.
It is possible for a remote user to cause a denial of service on a host running DSL_Vdns. Submitting data to port 6070 and closing the connection before the request is fulfilled, will cause DSL_Vdns to enter a 'Default.Closed' state; therefore, refusing any new connections.
Exploit / POC
Hughes Technologies DSL_Vdns Denial of Service Vulnerability
<[email protected]> has provided the following exploit:
<[email protected]> has provided the following exploit:
Solution / Fix
Hughes Technologies DSL_Vdns Denial of Service Vulnerability
Solution:
DSL_Vdns version 2.0 is not affected by this issue:
Hughes Technologies DSL_Vdns 1.0
Solution:
DSL_Vdns version 2.0 is not affected by this issue:
Hughes Technologies DSL_Vdns 1.0
-
Hughes Technologies vdns20
Windows
http://lhughes.hypermart.net/vdns20.zip -
Hughes Technologies vdnsl513
Linux Libc5
http://lhughes.hypermart.net/vdnsl513.tar.gz -
Hughes Technologies vdnsl613
Linux Libc6
http://lhughes.hypermart.net/vdnsl613.tar.gz
References
Hughes Technologies DSL_Vdns Denial of Service Vulnerability
References:
References:
- DSL_Vdns Hompage (Hughes Technologies)