Published:2011/01/21 Last Updated:2011/01/21
JVN#26605630
Cisco Linksys WRT54GC vulnerable to buffer overflow
Overview
Cisco Linksys WRT54GC provided by Cisco Systems contains a buffer overflow vulnerability.
Products Affected
- Cisco Linksys WRT54GC firmware prior to 1.6.01
Description
Cisco Linksys WRT54GC provided by Cisco Systems is a network router. Cisco Linksys WRT54GC contains a buffer overflow vulnerability.
Impact
When processing a specially crafted HTTP request, the router may crash resulting in a denial-of-service (DoS).
Solution
Update the software
Update to the latest version according to the information provided by the developer.
Vendor Status
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Analyzed on 2011.01.21
Measures | Conditions | Severity |
---|---|---|
Access Required | can be attacked over the Internet using packets |
|
Authentication | anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | the vulnerability can be exploited without an honest user taking any action |
|
Exploit Complexity | some expertise and/or luck required (most buffer overflows, guessing correctly in small space, expertise in Windows function calls) |
|
Credit
Yuji Ukai of Fourteenforty Research Institute, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2011-0352 |
JVN iPedia |
JVNDB-2011-000007 |
Update History
- 2011/01/21
- Information under the sections "References" was modified.