D-Link DI-614+ IP Fragment Reassembly Denial of Service Vulnerability
BID:7219
Info
D-Link DI-614+ IP Fragment Reassembly Denial of Service Vulnerability
| Bugtraq ID: | 7219 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 27 2003 12:00AM |
| Updated: | Mar 27 2003 12:00AM |
| Credit: | Announced by Thomas Reinke <[email protected]>. |
| Vulnerable: |
D-Link DI-614+ 2.0 |
| Not Vulnerable: | |
Discussion
D-Link DI-614+ IP Fragment Reassembly Denial of Service Vulnerability
It has been reported that the implementation of the Internet Protocol (IP) in the firmware of the D-Link DI-614+ wireless router is vulnerable to a remotely exploitable denial of service condition. The vulnerability is related to the reassembly of fragmented IP packets and can be triggered by transmission of fragments with malicious size parameters to an affected device. There is existing source code that exploits similar, older vulnerabilities that can be used to successfully exploit this vulnerability. When exploited, the device will reboot instantly. This will result in a denial of service until the device has restarted.
It has been reported that the implementation of the Internet Protocol (IP) in the firmware of the D-Link DI-614+ wireless router is vulnerable to a remotely exploitable denial of service condition. The vulnerability is related to the reassembly of fragmented IP packets and can be triggered by transmission of fragments with malicious size parameters to an affected device. There is existing source code that exploits similar, older vulnerabilities that can be used to successfully exploit this vulnerability. When exploited, the device will reboot instantly. This will result in a denial of service until the device has restarted.
Exploit / POC
D-Link DI-614+ IP Fragment Reassembly Denial of Service Vulnerability
Though the following exploit was not developed for this vulnerability, it reportedly triggers the condition:
Though the following exploit was not developed for this vulnerability, it reportedly triggers the condition:
References
D-Link DI-614+ IP Fragment Reassembly Denial of Service Vulnerability
References:
References:
- D-Link DI-614 wiresless router crash/reboots (Thomas Reinke
)