Multiple Linksys Devices Heap Corruption Denial Of Service
BID:6304
Info
Multiple Linksys Devices Heap Corruption Denial Of Service
| Bugtraq ID: | 6304 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2002 12:00AM |
| Updated: | Dec 03 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to CORE. |
| Vulnerable: |
Linksys EtherFast BEFSRU31 Router 1.43.3 Linksys EtherFast BEFSRU31 Router 1.43 Linksys EtherFast BEFSRU31 Router 1.42.7 Linksys EtherFast BEFSR81 Router 2.42.7 Linksys EtherFast BEFSR81 Router Linksys EtherFast BEFSR41 Router 1.43.3 Linksys EtherFast BEFSR41 Router 1.43 Linksys EtherFast BEFSR41 Router 1.42.7 Linksys EtherFast BEFSR11 Router 1.43.3 Linksys EtherFast BEFSR11 Router 1.43 Linksys EtherFast BEFSR11 Router 1.42.7 Linksys BEFW11S4 1.43.3 Linksys BEFW11S4 1.4.3 Linksys BEFW11S4 1.4.2 .7 Linksys BEFSX41 1.43.4 Linksys BEFSX41 1.43.3 Linksys BEFSX41 1.43 Linksys BEFN2PS4 1.42.7 |
| Not Vulnerable: |
Linksys EtherFast BEFSRU31 Router 1.44 Linksys EtherFast BEFSR81 Router 2.44 Linksys EtherFast BEFSR41 Router 1.44 Linksys EtherFast BEFSR11 Router 1.44 Linksys BEFW11S4 1.44 Linksys BEFSX41 1.44 |
Discussion
Multiple Linksys Devices Heap Corruption Denial Of Service
Several Linksys devices are prone to heap corruption.
Due to insufficient bounds checking when copying user-supplied input to memory, it may be possible to corrupt information stored in heap memory. This issue can be triggered through a malicious HTTP request to a vulnerable device.
This vulnerability may be exploited by an attacker to reboot the vulnerable device. Although unconfirmed, it may also be possible to modify various configuration settings or execute malicious code.
Several Linksys devices are prone to heap corruption.
Due to insufficient bounds checking when copying user-supplied input to memory, it may be possible to corrupt information stored in heap memory. This issue can be triggered through a malicious HTTP request to a vulnerable device.
This vulnerability may be exploited by an attacker to reboot the vulnerable device. Although unconfirmed, it may also be possible to modify various configuration settings or execute malicious code.
Exploit / POC
Multiple Linksys Devices Heap Corruption Denial Of Service
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Linksys Devices Heap Corruption Denial Of Service
Solution:
Linksys has released firmware 1.44 and 2.44 for several devices. Users are advised to download the newest firmware.
Linksys EtherFast BEFSR81 Router
Linksys BEFW11S4 1.4.2 .7
Linksys BEFW11S4 1.4.3
Linksys EtherFast BEFSR41 Router 1.42.7
Linksys EtherFast BEFSR11 Router 1.42.7
Linksys EtherFast BEFSRU31 Router 1.42.7
Linksys BEFN2PS4 1.42.7
Linksys EtherFast BEFSR41 Router 1.43
Linksys BEFSX41 1.43
Linksys EtherFast BEFSR11 Router 1.43
Linksys EtherFast BEFSRU31 Router 1.43
Linksys EtherFast BEFSRU31 Router 1.43.3
Linksys BEFW11S4 1.43.3
Linksys EtherFast BEFSR11 Router 1.43.3
Linksys EtherFast BEFSR41 Router 1.43.3
Linksys BEFSX41 1.43.3
Linksys BEFSX41 1.43.4
Linksys EtherFast BEFSR81 Router 2.42.7
Solution:
Linksys has released firmware 1.44 and 2.44 for several devices. Users are advised to download the newest firmware.
Linksys EtherFast BEFSR81 Router
-
Linksys Firmware 2.44
http://www.linksys.com/download/
Linksys BEFW11S4 1.4.2 .7
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys BEFW11S4 1.4.3
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys EtherFast BEFSR41 Router 1.42.7
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys EtherFast BEFSR11 Router 1.42.7
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys EtherFast BEFSRU31 Router 1.42.7
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys BEFN2PS4 1.42.7
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys EtherFast BEFSR41 Router 1.43
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys BEFSX41 1.43
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys EtherFast BEFSR11 Router 1.43
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys EtherFast BEFSRU31 Router 1.43
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys EtherFast BEFSRU31 Router 1.43.3
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys BEFW11S4 1.43.3
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys EtherFast BEFSR11 Router 1.43.3
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys EtherFast BEFSR41 Router 1.43.3
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys BEFSX41 1.43.3
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys BEFSX41 1.43.4
-
Linksys Firmware 1.44
http://www.linksys.com/download/
Linksys EtherFast BEFSR81 Router 2.42.7
-
Linksys Firmware 2.44
http://www.linksys.com/download/
References
Multiple Linksys Devices Heap Corruption Denial Of Service
References:
References: