ID

VAR-E-200602-0563


TITLE

Multiple D-Link Products IP Fragment Reassembly Denial of Service Vulnerability

Trust: 0.3

sources: BID: 16621

DESCRIPTION

Multiple D-Link devices are susceptible to a remote denial-of-service vulnerability. This issue is due to a flaw in affected devices that causes them to fail when attempting to reassemble certain IP packets.
This issue allows remote attackers to crash and reboot affected devices, denying service to legitimate users.
D-Link DI-524, DI-624, and Di-784 devices are affected by this issue. Due to code reuse among routers, other devices may also be affected.
It is reported that US Robotics USR8054 devices are also affected.

Trust: 0.3

sources: BID: 16621

AFFECTED PRODUCTS

vendor:u s roboticsmodel:usr8054scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:di-784scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:di-624scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:di-524scope:eqversion:3.20

Trust: 0.3

vendor:d linkmodel:di-524scope:eqversion:0

Trust: 0.3

vendor:d linkmodel:di-614+scope:neversion:2.30

Trust: 0.3

vendor:d linkmodel:di-614+scope:neversion:2.18

Trust: 0.3

vendor:d linkmodel:di-614+scope:neversion:2.10

Trust: 0.3

vendor:d linkmodel:di-614+ fscope:neversion:2.0

Trust: 0.3

vendor:d linkmodel:di-614+ 3gscope:neversion:2.0

Trust: 0.3

vendor:d linkmodel:di-614+scope:neversion:2.03

Trust: 0.3

vendor:d linkmodel:di-614+scope:neversion:2.0

Trust: 0.3

vendor:d linkmodel:di-604scope:neversion: -

Trust: 0.3

sources: BID: 16621

EXPLOIT

An exploit is not required.
An exploit by Aaron Portnoy is available that is designed to send packets that trigger this issue.
Bullet list:
<li><a href="/data/vulnerabilities/exploits/dlink_udp_dos.c">/data/vulnerabilities/exploits/dlink_udp_dos.c</a></li>

Trust: 0.3

sources: BID: 16621

PRICE

Free

Trust: 0.3

sources: BID: 16621

TYPE

Design Error

Trust: 0.3

sources: BID: 16621

CREDITS

Discovered by Aaron Portnoy <aportnoy@ccs.neu.edu>.

Trust: 0.3

sources: BID: 16621

EXTERNAL IDS

db:BIDid:16621

Trust: 0.3

sources: BID: 16621

REFERENCES

url:http://thunkers.net/~deft/advisories/dlink_udp_dos.txt

Trust: 0.3

url:http://www.d-link.com/

Trust: 0.3

url:http://www.usr.com/

Trust: 0.3

sources: BID: 16621

SOURCES

db:BIDid:16621

LAST UPDATE DATE

2022-07-27T10:02:13.839000+00:00


SOURCES UPDATE DATE

db:BIDid:16621date:2006-02-14T18:53:00

SOURCES RELEASE DATE

db:BIDid:16621date:2006-02-13T00:00:00