ID

VAR-200212-0881


TITLE

Multiple Linksys Device strcat() Remote Buffer Overflow Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2013-15342

DESCRIPTION

Linksys has developed a variety of broadband router devices, including BEFW11S4, BEFSRU31, etc., which includes a WEB management interface managed by HTTP. Multiple Linksys device management interfaces have problems handling the strcat() function. Remote attackers can exploit this vulnerability to perform denial of service attacks on devices and stop responding to normal communications. Since the strcat() function lacks the correct boundary buffer check for the input parameters, an attacker can exploit this vulnerability to send a malformed request to a Linksys device that has this vulnerability. When the device attempts to process malicious input, it can cause the memory information to be corrupted and the device to crash. Stop responding. This vulnerability can only be exploited when the device has UPnP (Universal Plug and Play) enabled.

Trust: 0.6

sources: CNVD: CNVD-2013-15342

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-15342

AFFECTED PRODUCTS

vendor:nomodel: - scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2013-15342

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-15342
value: LOW

Trust: 0.6

CNVD: CNVD-2013-15342
severity: LOW
baseScore: 0.0
vectorString: AV:L/AC:M/AU:N/C:N/I:N/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 0.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2013-15342

PATCH

title:Patch of multiple Linksys device strcat() remote buffer overflow vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/41838

Trust: 0.6

sources: CNVD: CNVD-2013-15342

EXTERNAL IDS

db:BIDid:63036303

Trust: 0.6

db:CNVDid:CNVD-2013-15342

Trust: 0.6

sources: CNVD: CNVD-2013-15342

REFERENCES

url:http://marc.theaimsgroup.com/?l=bugtraq&m=103893609009727&w=2

Trust: 0.6

sources: CNVD: CNVD-2013-15342

SOURCES

db:CNVDid:CNVD-2013-15342

LAST UPDATE DATE

2022-05-17T02:09:33.744000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-15342date:2013-12-19T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-15342date:2002-12-03T00:00:00