D-Link DIR-645 Command Injection and Stack Buffer Overflow Vulnerabilities
BID:72623
Info
D-Link DIR-645 Command Injection and Stack Buffer Overflow Vulnerabilities
| Bugtraq ID: | 72623 |
| Class: | Design Error |
| CVE: |
CVE-2015-2052 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2015 12:00AM |
| Updated: | Jul 15 2015 12:17AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
D-Link DIR-645 Command Injection and Stack Buffer Overflow Vulnerabilities
D-Link DIR-645 is prone to a command-injection and a stack-based buffer-overflow vulnerability.
An attacker can exploit these issues to cause arbitrary changes to memory and execute arbitrary shell commands or code as root.
D-Link DIR-645 is prone to a command-injection and a stack-based buffer-overflow vulnerability.
An attacker can exploit these issues to cause arbitrary changes to memory and execute arbitrary shell commands or code as root.
Exploit / POC
D-Link DIR-645 Command Injection and Stack Buffer Overflow Vulnerabilities
An attacker can exploit this issue using readily available commands and tools.
An attacker can exploit this issue using readily available commands and tools.
Solution / Fix
D-Link DIR-645 Command Injection and Stack Buffer Overflow Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
D-Link DIR-645 Command Injection and Stack Buffer Overflow Vulnerabilities
References:
References:
- D-Link Homepage (D-Link)