Full Disclosure mailing list archives

Re: DoS against AVM Fritz!Box 7050 (and others)


From: Matthias Wenzel <full-disclosure () mazzoo de>
Date: Tue, 23 Jan 2007 20:49:46 +0100

A new FW version with the fix is released:

ftp://ftp.avm.de/fritz.box/fritzbox.fon_wlan_7050/firmware/

Matthias

collin () betaversion net wrote:
Denial of Service against AVM Fritz!Box 7050 (and others)

Discovered by: Matthias Wenzel
Advisory: http://mazzoo.de/blog/2007/01/18#FritzBox_DoS

Manufacturer: AVM (www.avm.de)
Product: Fritz!Box 750 (and others)

Vendor was notified 6 month ago (see blog entry by Matthias)

Sending a zero-length UDP packet to port 5060 (SIP) of a AVM Fritz!Box will
crash the VoIP-telephony application. This works from any IP-interface,
including the DSL line.


Collin (only delivering the message to FD and BugTraq)


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: