Apple AirPort Express/Extreme WDS Denial of Service

secunia.com has reported a vulnerability in AirPort Express and Airport Extreme, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error in the communication handling when the device is configured in the Wireless Distribution System (WDS) mode. This can be exploited to cause a vulnerable device to stop responding by sending certain data via UDP on port 161.

Apple has released firmware updates to fix the vulnerability.

Solution:
Apply updated firmwares.

– Airport Express –

Update to firmware version 6.1.1.

Mac OS X:
http://www.apple.com/support/dow…expressfirmware611formacosx.html

Windows:
http://www.apple.com/support/dow…xpressfirmware611forwindows.html

– Airport Extreme –

Update to firmware version 5.5.1.

Mac OS X:
http://www.apple.com/support/dow…extremefirmware551formacosx.html

Windows:
http://www.apple.com/support/dow…xtremefirmware551forwindows.html


About this entry