Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_config function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the content in upload_file variable is NULL in the upload_config function then the strncasecmp would take NULL as first argument, and incur the NULL pointer dereference vulnerability.

Project Subscriptions

Vendors Products
Dap-2310 Subscribe
Dap-2310 Firmware Subscribe
Dap-2330 Subscribe
Dap-2330 Firmware Subscribe
Dap-2360 Subscribe
Dap-2360 Firmware Subscribe
Dap-2553 Subscribe
Dap-2553 Firmware Subscribe
Dap-2660 Subscribe
Dap-2660 Firmware Subscribe
Dap-2690 Subscribe
Dap-2690 Firmware Subscribe
Dap-2695 Subscribe
Dap-2695 Firmware Subscribe
Dap-3320 Subscribe
Dap-3320 Firmware Subscribe
Dap-3662 Subscribe
Dap-3662 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-15494 Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_config function of sbin/httpd binary. When the binary handle the specific HTTP GET request, the content in upload_file variable is NULL in the upload_config function then the strncasecmp would take NULL as first argument, and incur the NULL pointer dereference vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T21:55:11.626Z

Reserved: 2021-03-19T00:00:00

Link: CVE-2021-28840

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-10T18:15:07.220

Modified: 2024-11-21T06:00:18.510

Link: CVE-2021-28840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses