Linksys WRT54GL Unspecified Remote Buffer Overflow Vulnerability
BID:36262
Info
Linksys WRT54GL Unspecified Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 36262 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2009 12:00AM |
| Updated: | Sep 09 2009 06:31PM |
| Credit: | Intevydis |
| Vulnerable: |
Linksys WRT54GL 0 |
| Not Vulnerable: | |
Discussion
Linksys WRT54GL Unspecified Remote Buffer Overflow Vulnerability
Linksys WRT54GL is prone to an unspecified remote buffer-overflow vulnerability because it fails to bounds-check user-supplied input before copying it into an insufficiently sized memory buffer.
Exploiting this vulnerability may allow remote attackers to execute arbitrary code in the context of the affected device.
Linksys WRT54GL is prone to an unspecified remote buffer-overflow vulnerability because it fails to bounds-check user-supplied input before copying it into an insufficiently sized memory buffer.
Exploiting this vulnerability may allow remote attackers to execute arbitrary code in the context of the affected device.
Exploit / POC
Linksys WRT54GL Unspecified Remote Buffer Overflow Vulnerability
A working commercial exploit is available through Intevydis. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through Intevydis. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Linksys WRT54GL Unspecified Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Linksys WRT54GL Unspecified Remote Buffer Overflow Vulnerability
References:
References:
- Linksys Homepage (Linksys)
- VulnDisco Pack Professional (Intevydis)