Description: Jon Hart has reported a vulnerability in Linksys BEFSR41 and BEFW11S4, which can be exploited by malicious people to gain knowledge of sensitive information or cause a DoS (Denial of Service)
The vulnerability is caused due to an error within the integrated DHCP server when handling BOOTP packets. This can be exploited to make the device include portions of data from memory in DHCP replies or crash.
Solution: The vulnerability has been fixed in firmware version 1.05.00 for BEFSR41 ver3.
Provided and/or discovered by: Jon Hart (warchild[at]spoofed.org)
Changelog: 2004-05-14: Updated credits.
2004-05-24: Updated information in "Solution" section.
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.