Linksys EtherFast routers BOOTP packet denial of service

linksys-etherfast-bootp-dos (16142) The risk level is classified as MediumMedium Risk

Description:

Linksys EtherFast is vulnerable to a denial of service attack, caused by a vulnerability in the integrated DHCP server. By sending a specially-crafted BOOTP packet to the vulnerable device, a remote authenticated attacker could obtain sensitive information using a DHCP reply or cause the device to crash.


Consequences:

Denial of Service

Remedy:

For Linksys EtherFast BEFSR41 router version 1 and 2:
Upgrade to the latest firmware version (1.45.11 or later), available from the Linksys Firmware Download Web page. See References.

For Linksys EtherFast BEFSR41 router version 3:
Upgrade to the latest firmware version (1.05.00 or later), available from the Linksys Firmware Download Web page. See References.

References:

  • Linksys Firmware Download Web page: BEFSR41 - EtherFast® Cable/DSL Router with 4-Port Switch.
  • Linksys Firmware Download Web page: BEFSR41 - EtherFast® Cable/DSL Router with 4-Port Switch ver.3.
  • BID-10329: Multiple Linksys Devices DHCP Information Disclosure and Denial of Service Vulnerability
  • CVE-2004-0580: DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote attackers to obtain sensitive information.
  • OSVDB ID: 6325: Linksys BOOTP Remote Memory Information Disclosure
  • SA11606: Linksys BEF Series Routers DHCP Vulnerability
  • SECTRACK ID: 1010288: Linksys Routers May Disclose Kernel Memory Contents in Response to BOOTP Packets

Platforms Affected:

  • Linksys BEFCMU10
  • Linksys BEFN2PS4 1.42.7
  • Linksys BEFN2PS4
  • Linksys BEFSR11 1.40.2
  • Linksys BEFSR11 1.41
  • Linksys BEFSR11 1.42.3
  • Linksys BEFSR11 1.42.7
  • Linksys BEFSR11 1.43
  • Linksys BEFSR11 1.43.3
  • Linksys BEFSR11 1.44
  • Linksys BEFSR41 1.35
  • Linksys BEFSR41 1.36
  • Linksys BEFSR41 1.37
  • Linksys BEFSR41 1.38
  • Linksys BEFSR41 1.39
  • Linksys BEFSR41 1.40.2
  • Linksys BEFSR41 1.41
  • Linksys BEFSR41 1.42.3
  • Linksys BEFSR41 1.42.7
  • Linksys BEFSR41 1.43
  • Linksys BEFSR41 1.43.3
  • Linksys BEFSR41 1.44
  • Linksys BEFSR41 1.45.7
  • Linksys BEFSR41W
  • Linksys BEFSR81 2.42.7
  • Linksys BEFSR81
  • Linksys BEFSRU31 1.40.2
  • Linksys BEFSRU31 1.41
  • Linksys BEFSRU31 1.42.3
  • Linksys BEFSRU31 1.42.7
  • Linksys BEFSRU31 1.43
  • Linksys BEFSRU31 1.43.3
  • Linksys BEFSRU31 1.44
  • Linksys BEFSRU31 2.44
  • Linksys BEFSX41 1.42.7
  • Linksys BEFSX41 1.43
  • Linksys BEFSX41 1.43.3
  • Linksys BEFSX41 1.43.4
  • Linksys BEFSX41 1.44
  • Linksys BEFSX41 1.44.3
  • Linksys BEFSX41 1.45.3
  • Linksys BEFVP41 1.39.64
  • Linksys BEFVP41 1.40.3f
  • Linksys BEFVP41 1.40.4
  • Linksys BEFVP41 1.42.7
  • Linksys BEFVP41
  • Linksys RV082
  • Linksys WAP55AG 1.0.7
  • Linksys WRT54G 1.42.3
  • Linksys WRT54G 2.00.8

Reported:

May 13, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page