D-Link Multiple Products Unspecified Remote Buffer Overflow Vulnerability
BID:50405
Info
D-Link Multiple Products Unspecified Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 50405 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2011-3992 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2011 12:00AM |
| Updated: | Oct 28 2011 12:00AM |
| Credit: | Hisashi Kojima, Masahiro Nakada, Fujitsu Laboratories |
| Vulnerable: |
D-Link DWL-3200AP 0 D-Link DWL-2100AP 0 D-Link DES-3800 0 |
| Not Vulnerable: |
D-Link DWL-3200AP Firmware 2.55RC549 D-Link DWL-2100AP Firmware 2.50RC548 D-Link DES-3800 Firmware R4.50B052 |
Discussion
D-Link Multiple Products Unspecified Remote Buffer Overflow Vulnerability
Multiple D-Link products are prone to a remote buffer-overflow vulnerability because they fail to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Very few details are available regarding this issue. We will update this BID when more information emerges.
An attacker can exploit this issue to execute arbitrary code in the context of the affected applications. Failed exploit attempts will likely result in a denial-of-service condition.
The issue affects the following:
D-Link DES-3800 firmware prior to R4.50B052
D-Link DWL-2100AP firmware prior to 2.50RC548
D-Link DWL-3200AP firmware prior to 2.55RC549
Multiple D-Link products are prone to a remote buffer-overflow vulnerability because they fail to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Very few details are available regarding this issue. We will update this BID when more information emerges.
An attacker can exploit this issue to execute arbitrary code in the context of the affected applications. Failed exploit attempts will likely result in a denial-of-service condition.
The issue affects the following:
D-Link DES-3800 firmware prior to R4.50B052
D-Link DWL-2100AP firmware prior to 2.50RC548
D-Link DWL-3200AP firmware prior to 2.55RC549
Exploit / POC
D-Link Multiple Products Unspecified Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
D-Link Multiple Products Unspecified Remote Buffer Overflow Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
References
D-Link Multiple Products Unspecified Remote Buffer Overflow Vulnerability
References:
References: