多家厂商无线接入点内嵌HTTP服务程序远程拒绝服务攻击漏洞

多家厂商无线接入点内嵌HTTP服务程序远程拒绝服务攻击漏洞

漏洞ID 1107076 漏洞类型 边界条件错误
发布时间 2002-11-01 更新时间 2005-10-20
图片[1]-多家厂商无线接入点内嵌HTTP服务程序远程拒绝服务攻击漏洞-安全小百科CVE编号 CVE-2002-1865
图片[2]-多家厂商无线接入点内嵌HTTP服务程序远程拒绝服务攻击漏洞-安全小百科CNNVD-ID CNNVD-200212-477
漏洞平台 Hardware CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21978
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-477
|漏洞详情
多家厂商无线接入点设备中内嵌HTTP服务程序。多家厂商无线接入点设备中内嵌HTTP服务程序对超长HTTP请求处理不正确,远程攻击者可以利用这个漏洞对无线接入设备进行拒绝服务攻击。攻击者可以发送包含超多字符串的Host:字段的畸形HTTP请求,可导致设备停止对正常通信的响应,产生拒绝服务。需要重新启动设备才能恢复正常功能。虽然没有证实,但应该是由于缓冲区溢出造成的,可能存在以WEB进程的权限在系统上执行任意指令的机会。
|漏洞EXP
source: http://www.securityfocus.com/bid/6090/info

A denial of service vulnerability has been reported for several networking devices.

The condition will be triggered when the embedded web server, used by the devices, receives an overly long HTTP header. An attacker can exploit this vulnerability to cause the device to stop functioning.

Rebooting the device is necessary to restore functionality.

Although not yet confirmed, it has been speculated that this issue is a result of a buffer overflow. 

GET / HTTP/1.1
Host: <lots of characters>
|参考资料

来源:BID
名称:6090
链接:http://www.securityfocus.com/bid/6090
来源:XF
名称:ap-embedded-http-dos(10537)
链接:http://www.iss.net/security_center/static/10537.php
来源:VULNWATCH
名称:20021101Re:IDEFENSEDOSinLinksysBEFSR41EtherFastCable/DSLRouter+MoreissuesDLINK&LINKSYS;
链接:http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0052.html
来源:NSFOCUS
名称:3765
链接:http://www.nsfocus.net/vulndb/3765

相关推荐: PhpMyFaq index.php目录遍历漏洞

PhpMyFaq index.php目录遍历漏洞 漏洞ID 1109089 漏洞类型 路径遍历 发布时间 2005-09-23 更新时间 2005-09-23 CVE编号 CVE-2005-3048 CNNVD-ID CNNVD-200509-244 漏洞平台…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享