Cisco Linksys WRT54GC HTTP Request Buffer Overflow Vulnerability


Description   A vulnerability has been identified in Cisco Linksys WRT54GC, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable device. This issue is caused by a buffer overflow error in the web-based management interface when processing malformed HTTP POST requests, which could be exploited by remote unauthenticated attackers to cause a vulnerable device to stop responding or execute arbitrary code.
     
Vulnerable Products   Vulnerable Software:
Cisco Linksys WRT54GC firmware versions prior to 1.06.1
     
Solution   Upgrade to Cisco Linksys WRT54GC firmware version 1.06.1 : http://homedownloads.cisco.com/downloads/firmware/WRT54GCv1_US_FW_1.06.1.ZIP
     
CVE   CVE-2011-0352
     
References   http://tools.cisco.com/security/center/viewAlert.x?alertId=22228
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Critical 

 Vulnerability First Public Report Date 
2011-01-25 

 Target Type 
Server 

 Possible exploit 
Local & Remote