PT-2006-2095 · Linksys · Linksys Wrt54G
Hm2K
·
Published
2006-03-07
·
Updated
2018-10-18
·
CVE-2006-1067
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Linksys WRT54G routers version 5
Description
The issue allows remote attackers to cause a denial of service by sending a malformed DCC SEND string to an IRC channel. This results in an IRC connection reset and may be related to the masquerading code for NAT environments. The denial of service can be triggered by sending a DCC SEND with a single long argument or a DCC SEND with IP, port, and filesize arguments with a 0 value.
Recommendations
For Linksys WRT54G routers version 5, consider restricting access to IRC channels to minimize the risk of exploitation until a fix is available. As a temporary workaround, avoid using the DCC SEND feature in IRC connections.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linksys Wrt54G