ID

VAR-200505-0585


CVE

CVE-2005-0289


TITLE

Apple AirPort Wireless Distributed System Remote Denial of Service Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200505-076

DESCRIPTION

Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a denial of service (device freeze) by connecting to UDP port 161 and before link-state change occurs. This issue could allow a remote attacker to cause the base station to stop processing traffic. This can be exploited to cause a vulnerable device to stop responding by sending certain data via UDP on port 161. SOLUTION: Apply updated firmwares. -- Airport Express -- Update to firmware version 6.1.1. Mac OS X: http://www.apple.com/support/downloads/airportexpressfirmware611formacosx.html Windows: http://www.apple.com/support/downloads/airportexpressfirmware611forwindows.html -- Airport Extreme -- Update to firmware version 5.5.1. Mac OS X: http://www.apple.com/support/downloads/airportextremefirmware551formacosx.html Windows: http://www.apple.com/support/downloads/airportextremefirmware551forwindows.html PROVIDED AND/OR DISCOVERED BY: Dylan Griffiths ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 1.35

sources: NVD: CVE-2005-0289 // BID: 12152 // VULHUB: VHN-11498 // PACKETSTORM: 35719

AFFECTED PRODUCTS

vendor:applemodel:airport extremescope:lteversion:5.5

Trust: 1.0

vendor:applemodel:airport expressscope:lteversion:6.1

Trust: 1.0

vendor:applemodel:airport extremescope:eqversion:5.5

Trust: 0.9

vendor:applemodel:airport expressscope:eqversion:6.1

Trust: 0.9

sources: BID: 12152 // CNNVD: CNNVD-200505-076 // NVD: CVE-2005-0289

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2005-0289
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200505-076
value: MEDIUM

Trust: 0.6

VULHUB: VHN-11498
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2005-0289
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-11498
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-11498 // CNNVD: CNNVD-200505-076 // NVD: CVE-2005-0289

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2005-0289

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200505-076

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-200505-076

EXTERNAL IDS

db:BIDid:12152

Trust: 2.0

db:NVDid:CVE-2005-0289

Trust: 2.0

db:SECUNIAid:13753

Trust: 1.8

db:CNNVDid:CNNVD-200505-076

Trust: 0.7

db:BUGTRAQid:20050115 APPLE AIRPORT WDS DOS

Trust: 0.6

db:XFid:18865

Trust: 0.6

db:VULHUBid:VHN-11498

Trust: 0.1

db:PACKETSTORMid:35719

Trust: 0.1

sources: VULHUB: VHN-11498 // BID: 12152 // PACKETSTORM: 35719 // CNNVD: CNNVD-200505-076 // NVD: CVE-2005-0289

REFERENCES

url:http://www.securityfocus.com/bid/12152

Trust: 1.7

url:http://secunia.com/advisories/13753

Trust: 1.7

url:http://lists.grok.org.uk/pipermail/full-disclosure/2005-january/030832.html

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/18865

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=110582124528867&w=2

Trust: 1.0

url:http://marc.theaimsgroup.com/?l=bugtraq&m=110582124528867&w=2

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/18865

Trust: 0.6

url:http://www.apple.com/support/airport/

Trust: 0.3

url:/archive/1/387311

Trust: 0.3

url:http://marc.info/?l=bugtraq&m=110582124528867&w=2

Trust: 0.1

url:http://secunia.com/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/advisories/13753/

Trust: 0.1

url:http://www.apple.com/support/downloads/airportexpressfirmware611formacosx.html

Trust: 0.1

url:http://www.apple.com/support/downloads/airportextremefirmware551forwindows.html

Trust: 0.1

url:http://www.apple.com/support/downloads/airportextremefirmware551formacosx.html

Trust: 0.1

url:http://www.apple.com/support/downloads/airportexpressfirmware611forwindows.html

Trust: 0.1

url:http://secunia.com/product/4504/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/product/4503/

Trust: 0.1

url:http://secunia.com/about_secunia_advisories/

Trust: 0.1

sources: VULHUB: VHN-11498 // BID: 12152 // PACKETSTORM: 35719 // CNNVD: CNNVD-200505-076 // NVD: CVE-2005-0289

CREDITS

Discovery is credited to Dylan Griffiths <dylang@thock.com>.

Trust: 0.9

sources: BID: 12152 // CNNVD: CNNVD-200505-076

SOURCES

db:VULHUBid:VHN-11498
db:BIDid:12152
db:PACKETSTORMid:35719
db:CNNVDid:CNNVD-200505-076
db:NVDid:CVE-2005-0289

LAST UPDATE DATE

2024-08-14T14:35:48.846000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-11498date:2017-07-11T00:00:00
db:BIDid:12152date:2009-07-12T09:26:00
db:CNNVDid:CNNVD-200505-076date:2005-10-20T00:00:00
db:NVDid:CVE-2005-0289date:2017-07-11T01:32:11.953

SOURCES RELEASE DATE

db:VULHUBid:VHN-11498date:2005-05-02T00:00:00
db:BIDid:12152date:2005-01-03T00:00:00
db:PACKETSTORMid:35719date:2005-01-15T23:22:02
db:CNNVDid:CNNVD-200505-076date:2005-05-02T00:00:00
db:NVDid:CVE-2005-0289date:2005-05-02T04:00:00