D-Link WBR-2310 Web Server HTTP GET Request Remote Buffer Overflow Vulnerability
BID:42153
Info
D-Link WBR-2310 Web Server HTTP GET Request Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 42153 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2010 12:00AM |
| Updated: | Aug 03 2010 12:00AM |
| Credit: | Rodrigo Escobar |
| Vulnerable: |
D-Link WBR-2310 1.0.4 |
| Not Vulnerable: | |
Discussion
D-Link WBR-2310 Web Server HTTP GET Request Remote Buffer Overflow Vulnerability
D-Link WBR-2310 is prone to a remote buffer-overflow vulnerability because it fails to bounds-check user-supplied input before copying it into an insufficiently sized memory buffer. This issue occurs in the device's webserver.
Exploiting this vulnerability may allow remote attackers to execute arbitrary code in the context of the affected devices webserver.
D-Link WBR-2310 firmware version 1.04 is vulnerable; other versions may also be affected.
D-Link WBR-2310 is prone to a remote buffer-overflow vulnerability because it fails to bounds-check user-supplied input before copying it into an insufficiently sized memory buffer. This issue occurs in the device's webserver.
Exploiting this vulnerability may allow remote attackers to execute arbitrary code in the context of the affected devices webserver.
D-Link WBR-2310 firmware version 1.04 is vulnerable; other versions may also be affected.
Exploit / POC
D-Link WBR-2310 Web Server HTTP GET Request Remote Buffer Overflow Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
D-Link WBR-2310 Web Server HTTP GET Request Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
D-Link WBR-2310 Web Server HTTP GET Request Remote Buffer Overflow Vulnerability
References:
References:
- D-Link Homepage (D-Link)
- [DCA-00014] Dlink WBR-2310 Wireless Router DoS (Rodrigo Escobar
)