
Bugtraqmailing list archives
Apple Airport WDS DoS
From: Dylan Griffiths <dylang () thock com>
Date: Sat, 15 Jan 2005 11:58:31 -0600
Thock.com Security AdvisoryProblem: Apple AirPort WDS DoSAffected devices: AirPort Extreme and Airport Express.Severity: Denial of service.Author: Dylan Griffiths <dylang () thock com>Vendor Status: Fix available.Overview:Apple's AirPort devices are wireless access points, providing802.11 services to network clients. One popular configuration is theWDS which causes each access point to act like a physical port on avirtual switch, forwarding packets between two or more wired segments ofa network.Details:When configured in a WDS, Apple's Airport Extreme and Expressbasestations can be made to crash when a UDP port is connected to, andthen a link-state change occurs. The software responsible for bridgingpackets between the wired and wireless sides will stop responding, andthe entire device will lock up (the status lights will not indicate anerror).Vendor Response:New firmware has been released for both devices. Update yourWDS-enabled networks to the latest firmware as soon as possible.Special thanks to John Clecak at Apple for working with me to isolateand correct this bug!Airport Express 6.1.1 firmwareMacOSX:http://www.apple.com/support/downloads/airportexpressfirmware611formacosx.htmlWindows:http://www.apple.com/support/downloads/airportexpressfirmware611forwindows.htmlAirport Extreme 5.5.1 firmwareMacOSX:http://www.apple.com/support/downloads/airportextremefirmware551formacosx.htmlWindows:http://www.apple.com/support/downloads/airportextremefirmware551forwindows.html
Current thread:
- Apple Airport WDS DoSDylan Griffiths (Jan 15)
