Aidden
06-08-04, 09:37 AM
Linksys has released fixes for numerous known security holes within its router
line that have recently come under scrutiny from the community.
A new firmware version 1.45.11, dated June 4, specifically mentions closing
the BOOTP and memory leak hole which allowed remote sniffing of TCP/IP traffic
passing through the devices has now supposedly been resolved.</p>
Here is a list of the fixes listed in the firmware release notes:</p>
<ul>
*Fixed CGI string attacks issue
* Fixed UPnP on Windows XP SP2 issue
*Fixed One way audio issue
*Fixed NAT-T issue for some VPN connection
*Fixed DHCP server revision, fill the siaddr to the server address
*Fixed DHCP (BOOTP) vulnerability issue
*Added Filter IDENT(port 113) to appear stealth when scanned
*Added DHCP option 55 support
*Fixed buffer leakage bug
*Modified TCP Support RFC 3360 standard
*Modified PPPoE/L2TP/PPTP fragmentation supports fragmenting 1 packet into more than 3
*Modified MTU/MRU function for better handling
[/list]
You can access the Linksys firmware upgrade here (http://www.linksys.com/support/support.asp)</p>
line that have recently come under scrutiny from the community.
A new firmware version 1.45.11, dated June 4, specifically mentions closing
the BOOTP and memory leak hole which allowed remote sniffing of TCP/IP traffic
passing through the devices has now supposedly been resolved.</p>
Here is a list of the fixes listed in the firmware release notes:</p>
<ul>
*Fixed CGI string attacks issue
* Fixed UPnP on Windows XP SP2 issue
*Fixed One way audio issue
*Fixed NAT-T issue for some VPN connection
*Fixed DHCP server revision, fill the siaddr to the server address
*Fixed DHCP (BOOTP) vulnerability issue
*Added Filter IDENT(port 113) to appear stealth when scanned
*Added DHCP option 55 support
*Fixed buffer leakage bug
*Modified TCP Support RFC 3360 standard
*Modified PPPoE/L2TP/PPTP fragmentation supports fragmenting 1 packet into more than 3
*Modified MTU/MRU function for better handling
[/list]
You can access the Linksys firmware upgrade here (http://www.linksys.com/support/support.asp)</p>