SkyStream EMR5000 1.16 through 1.18 does not drop packets or disable the Ethernet interface when the buffers are full, which allows remote attackers to cause a denial of service (null pointer exception and kernel panic) via a large number of packets.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/5977 | vdb entry third party advisory broken link |
http://www.iss.net/security_center/static/10380.php | vdb entry broken link |
http://www.securityfocus.com/archive/1/295516 | mailing list vdb entry third party advisory broken link |
http://www.globalintersec.com/adv/skystream-2002021001.txt | exploit patch broken link |