Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.

Project Subscriptions

Vendors Products
Dir-868l Subscribe
Dir-868l Firmware Subscribe
Dir-880l Subscribe
Dir-880l Firmware Subscribe
Dir-885l Subscribe
Dir-885l Firmware Subscribe
Dir-890l Subscribe
Dir-890l Firmware Subscribe
Dir-895l Subscribe
Dir-895l Firmware Subscribe
Dir-895r Subscribe
Dir-895r Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2017-6425 Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T19:42:22.242Z

Reserved: 2017-09-29T00:00:00.000Z

Link: CVE-2017-14948

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-14T18:15:10.263

Modified: 2024-11-21T03:13:49.407

Link: CVE-2017-14948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses