Linksys EtherFast null length IP option denial of service

linksys-null-length-dos (24125) The risk level is classified as LowLow Risk

Description:

Linksys EtherFast is vulnerable to a denial of service attack. A remote attacker could send a specially-crafted packet containing a NULL length IP option to cause the device to crash. The device must be rebooted to regain normal functionality.

Platforms Affected:

  • Linksys, BEFVP41

Remedy:

No remedy available as of July 4, 2009.

Consequences:

Denial of Service

References:

  • BugTraq Mailing List, Fri Jan 13 2006 - 00:17:45 CST, Linksys VPN Router (BEFVP41) DoS Vulnerability at http://archives.neohapsis.com/archives/bugtraq/2006-01/0249.html.
  • BID-16307: Linksys BEFVP41 IP Options Remote Denial Of Service Vulnerability
  • CVE-2006-0309: Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length.
  • SA18461: Linksys BEFVP41 IP Option Length Denial of Service
  • SECTRACK ID: 1015490: Linksys BEFVP41 VPN Router Can Be Crashed By Remote Users
  • VUPEN/ADV-2006-0238: Linksys BEFVP41 IP Option Length Remote Denial of Service Vulnerability

Reported:

Jan 13, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page