Netopia Timbuktu Pro 2.0 DoS Vulnerability
BID:984
Info
Netopia Timbuktu Pro 2.0 DoS Vulnerability
| Bugtraq ID: | 984 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2000-0142 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 11 2000 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | Posted to Bugtraq on February 11, 2000 by Laurent Levier <[email protected]>. |
| Vulnerable: |
Netopia Timbuktu Pro Remote Control 5.2.1 Netopia Timbuktu Pro Remote Control 2.0 |
| Not Vulnerable: |
Netopia Timbuktu Pro 2000 |
Discussion
Netopia Timbuktu Pro 2.0 DoS Vulnerability
Simple connections and disconnections to Timbuktu ports can hang the authentication process and halt all Timbuktu services. To return to normal functionality, the Timbuktu process will need to be killed and the Timbuktu service is required to be stopped and restarted.
Simple connections and disconnections to Timbuktu ports can hang the authentication process and halt all Timbuktu services. To return to normal functionality, the Timbuktu process will need to be killed and the Timbuktu service is required to be stopped and restarted.
Exploit / POC
Netopia Timbuktu Pro 2.0 DoS Vulnerability
Connect and disconnect on TCP port 407.
Connect and disconnect on TCP port 1417.
Note: no data needs to be transferred.
MBernheim <[email protected]> has released the following shell script exploit:
Connect and disconnect on TCP port 407.
Connect and disconnect on TCP port 1417.
Note: no data needs to be transferred.
MBernheim <[email protected]> has released the following shell script exploit:
Solution / Fix
Netopia Timbuktu Pro 2.0 DoS Vulnerability
Solution:
This issue has been resolved in Timbuktu Pro 2000.
Solution:
This issue has been resolved in Timbuktu Pro 2000.
References
Netopia Timbuktu Pro 2.0 DoS Vulnerability
References:
References: