Researcher Roots Out D-Link Wireless Bug


CRN logo By Kevin McLaughlin, ChannelWeb

6:22 PM EDT Tue. Jun. 12, 2007
Symantec Tuesday warned of an unpatched vulnerability in a D-Link wireless device driver that could enable an attacker to create a denial of service situation or compromise an affected PC. The flaw affects the wireless driver for D-Link's DWL-G650+, which connects notebook PCs to 802.11 b/g WLANs.

An error that occurs when the driver processes malformed beacon frames could enable an attacker to trigger a buffer overflow and execute malicious code, Symantec said in a Deepsight Threat Management System bulletin.

However, to exploit the vulnerability, a hacker would have to be in range of the wireless connection on the device, Symantec said.

The vulnerability exists on Windows XP and affects version 6.0.0.18 (Rev. A1) of the driver, and other drivers are also potentially vulnerable, according to Symantec.

Symantec, which rated the severity of the vulnerability as 9.4 out of 10, said it isn't aware of any patch, and recommended that users disable wireless network cards when in public areas.

D-Link could not be reached for comment.

Symantec credited Laurent Butti, a researcher with the R&D unit of France Telecom's Orange division, with discovering the flaw. Butti, who has developed his own 802.11 'fuzzing' tool, in March provided details on the D-Link vulnerability at Black Hat Europe in Amsterdam.

Last November, security researchers from the Month Of Kernel Bugs project discovered a buffer overflow vulnerability in the wireless driver that ships with the widely used D-Link DWL-G132 wireless USB adapter.

 
Channelweb : Promofinder
FEATURED PROMOTIONS
30% off Virtualization Manager 2010 Corporate
Save 30% on Paragon Software Virtualization Manager 2010 Corporate. Our response to the typical problems of every modern comp...
Endian UTM Empowering VARS
Endian empowers VARs with Partners Rock! Channel Program.
RELATED BLOG >>
Photo
Delfigo's flagship DS Gateway touts a zero-footprint installation with its cloud architecture, eliminating the need for flash downloads and hardware tokens.
Media Kits | Reprints | Privacy Statement | Copyright © 2010 United Business Media LLC | Terms of Service
CRN Logo ChannelWeb Logo CRN Logo CRNTech Logo Everything Channel Events IPED
ADVERTISEMENT




CHANNEL SERVICES >>