CVE-2007-4915: Input Validation
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password stored in memory via a long username in an HTTP Basic Authentication request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4915?
CVE-2007-4915 is considered a high severity vulnerability due to the potential for remote code execution via crafted input.
How do I fix CVE-2007-4915?
To fix CVE-2007-4915, update the Boa web server to a version later than 0.93.15 that addresses this vulnerability.
What type of devices are affected by CVE-2007-4915?
CVE-2007-4915 affects devices using the Boa web server version 0.93.15, including FreeLan RO80211G-AP.
What exploit does CVE-2007-4915 enable?
CVE-2007-4915 allows remote attackers to change the admin password by using a long username in an HTTP Basic Authentication request.
Can CVE-2007-4915 be exploited without authentication?
Yes, CVE-2007-4915 can be exploited without authentication since it allows attackers to manipulate memory directly.