ID
VAR-201203-0517
TITLE
Multiple Remote Code Execution Vulnerabilities in Multiple Xerox Devices
Trust: 0.6
DESCRIPTION
Multiple Xerox products have multiple security vulnerabilities that allow malicious users to gain control of the device. Xerox has an unspecified security error that allows an attacker to send a specially crafted postscript or firmware job to execute arbitrary code. No detailed vulnerability details are currently available. An attacker can exploit these issues to execute arbitrary code in the context of the affected application. Successful exploitation can completely compromise the vulnerable device. ---------------------------------------------------------------------- Become a PSI 3.0 beta tester! Test-drive the new beta version and tell us what you think about its extended automatic update function and significantly enhanced user-interface. Download it here! http://secunia.com/psi_30_beta_launch ---------------------------------------------------------------------- TITLE: Xerox Products PostScript and DLM Vulnerabilities SECUNIA ADVISORY ID: SA48322 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/48322/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=48322 RELEASE DATE: 2012-03-14 DISCUSS ADVISORY: http://secunia.com/advisories/48322/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/48322/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=48322 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Two vulnerabilities have been reported in multiple Xerox products, which can be exploited by malicious people to compromise a vulnerable device. Please see the vendor's advisory for the list of affected products. SOLUTION: Apply update or workaround if available (please see the vendor's advisory for details). PROVIDED AND/OR DISCOVERED BY: The vendor credits Deral Heiland, www.foofus.net and Andrei Costin, www.andreicostin.com ORIGINAL ADVISORY: XRX12-003: http://www.xerox.com/download/security/security-bulletin/1284332-2ddc5-4baa79b70ac40/cert_XRX12-003_v1.1.pdf OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------
Trust: 0.9
IOT TAXONOMY
| category: | ['Network device'] | sub_category: | - | Trust: 0.6 |
AFFECTED PRODUCTS
| vendor: | xerox | model: | colorqube | scope: | eq | version: | 8870 | Trust: 0.9 |
| vendor: | xerox | model: | colorqube | scope: | eq | version: | 8570 | Trust: 0.9 |
| vendor: | xerox | model: | colorqube series | scope: | eq | version: | 9300 | Trust: 0.6 |
| vendor: | xerox | model: | colorqube series | scope: | eq | version: | 9200 | Trust: 0.6 |
| vendor: | xerox | model: | workcentre | scope: | - | version: | - | Trust: 0.6 |
| vendor: | xerox | model: | phaser 3160n | scope: | - | version: | - | Trust: 0.6 |
| vendor: | xerox | model: | color | scope: | eq | version: | 550/560 | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 3250 | Trust: 0.6 |
| vendor: | xerox | model: | phaser 3300mfp | scope: | - | version: | - | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 3435 | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 3600 | Trust: 0.6 |
| vendor: | xerox | model: | phaser 3635mfp | scope: | - | version: | - | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 4510 | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 4600/4620 | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 5550 | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 6300/6350 | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 6360 | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 6700 | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 7760 | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 7800 | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 8500/8550 | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 8560 | Trust: 0.6 |
| vendor: | xerox | model: | phaser 8560mfp | scope: | - | version: | - | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 8860 | Trust: 0.6 |
| vendor: | xerox | model: | phaser 8860mfp | scope: | - | version: | - | Trust: 0.6 |
| vendor: | xerox | model: | workcentre pro | scope: | - | version: | - | Trust: 0.6 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 7500 | Trust: 0.6 |
| vendor: | xerox | model: | workcentre pro color | scope: | eq | version: | 3545 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro color | scope: | eq | version: | 2636 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro color | scope: | eq | version: | 2128 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 90 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 75 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 65 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 55 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 45 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro color | scope: | eq | version: | 40 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 35 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro color | scope: | eq | version: | 32 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 2750 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 2550 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 2450 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 2380 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 175 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 165 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 265 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre pro | scope: | eq | version: | 232 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre m55 | scope: | - | version: | - | Trust: 0.3 |
| vendor: | xerox | model: | workcentre m45 | scope: | - | version: | - | Trust: 0.3 |
| vendor: | xerox | model: | workcentre m35 | scope: | - | version: | - | Trust: 0.3 |
| vendor: | xerox | model: | workcentre m175 | scope: | - | version: | - | Trust: 0.3 |
| vendor: | xerox | model: | workcentre m165 | scope: | - | version: | - | Trust: 0.3 |
| vendor: | xerox | model: | workcentre bookmark | scope: | eq | version: | 55 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre bookmark | scope: | eq | version: | 40 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 76750 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 76650 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 76550 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre m20i | scope: | - | version: | - | Trust: 0.3 |
| vendor: | xerox | model: | workcentre m20 | scope: | - | version: | - | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7775 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7765 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7755 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7556 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7545 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7535 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7530 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7525 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7435 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7428 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7425 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7346 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7345 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7335 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7328 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7245 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7242 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7235 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7232 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7228 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7132 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7125 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 7120 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 6400 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5675 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5665 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5655 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5645 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5638 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5632 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5335 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5330 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5325 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5230 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5225 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5222 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5150 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5135 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5050 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 5030 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 4260 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 4250 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 4150 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 4118 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 3550 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 3220 | Trust: 0.3 |
| vendor: | xerox | model: | workcentre | scope: | eq | version: | 3210 | Trust: 0.3 |
| vendor: | xerox | model: | phaser 8860mfp | scope: | eq | version: | 0 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 88600 | Trust: 0.3 |
| vendor: | xerox | model: | phaser 8560mfp | scope: | eq | version: | 0 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 85600 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 85500 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 78000 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 77600 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 75000 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 74000 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 63600 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 63500 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 55500 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 46200 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 46000 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 45100 | Trust: 0.3 |
| vendor: | xerox | model: | phaser 3635mfp | scope: | eq | version: | 0 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 36000 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 34350 | Trust: 0.3 |
| vendor: | xerox | model: | phaser 3300mfp | scope: | eq | version: | 0 | Trust: 0.3 |
| vendor: | xerox | model: | phaser | scope: | eq | version: | 32500 | Trust: 0.3 |
| vendor: | xerox | model: | phaser 3160n | scope: | eq | version: | 0 | Trust: 0.3 |
| vendor: | xerox | model: | colorqube | scope: | eq | version: | 9303 | Trust: 0.3 |
| vendor: | xerox | model: | colorqube | scope: | eq | version: | 9302 | Trust: 0.3 |
| vendor: | xerox | model: | colorqube | scope: | eq | version: | 9301 | Trust: 0.3 |
| vendor: | xerox | model: | colorqube | scope: | eq | version: | 9203 | Trust: 0.3 |
| vendor: | xerox | model: | colorqube | scope: | eq | version: | 9202 | Trust: 0.3 |
| vendor: | xerox | model: | colorqube | scope: | eq | version: | 9201 | Trust: 0.3 |
THREAT TYPE
network
Trust: 0.3
TYPE
Boundary Condition Error
Trust: 0.3
PATCH
| title: | Patch for multiple remote code execution vulnerabilities for multiple Xerox devices | url: | https://www.cnvd.org.cn/patchinfo/show/13452 | Trust: 0.6 |
EXTERNAL IDS
| db: | BID | id: | 52483 | Trust: 0.9 |
| db: | SECUNIA | id: | 48322 | Trust: 0.7 |
| db: | CNVD | id: | CNVD-2012-1342 | Trust: 0.6 |
| db: | PACKETSTORM | id: | 110784 | Trust: 0.1 |
REFERENCES
| url: | http://secunia.com/advisories/48322/ | Trust: 0.7 |
| url: | http://www.xerox.com/download/security/security-bulletin/1284332-2ddc5-4baa79b70ac40/cert_xrx12-003_v1.1.pdf | Trust: 0.4 |
| url: | http://h.foofus.net/goons/percx/xerox_hack.pdf | Trust: 0.3 |
| url: | http://www.xerox.com | Trust: 0.3 |
| url: | https://www.rapid7.com/db/modules/exploit/unix/misc/xerox_mfp | Trust: 0.3 |
| url: | http://seclists.org/fulldisclosure/2016/apr/91 | Trust: 0.3 |
| url: | https://www.andreicostin.com | Trust: 0.1 |
| url: | http://secunia.com/psi_30_beta_launch | Trust: 0.1 |
| url: | http://secunia.com/vulnerability_intelligence/ | Trust: 0.1 |
| url: | http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ | Trust: 0.1 |
| url: | http://secunia.com/advisories/secunia_security_advisories/ | Trust: 0.1 |
| url: | http://secunia.com/advisories/48322/#comments | Trust: 0.1 |
| url: | http://secunia.com/vulnerability_scanning/personal/ | Trust: 0.1 |
| url: | https://ca.secunia.com/?page=viewadvisory&vuln_id=48322 | Trust: 0.1 |
| url: | http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org | Trust: 0.1 |
| url: | https://www.foofus.net | Trust: 0.1 |
| url: | http://secunia.com/advisories/about_secunia_advisories/ | Trust: 0.1 |
CREDITS
The vendor reported these issues.
Trust: 0.3
SOURCES
| db: | CNVD | id: | CNVD-2012-1342 |
| db: | BID | id: | 52483 |
| db: | PACKETSTORM | id: | 110784 |
LAST UPDATE DATE
2022-05-17T22:24:28.923000+00:00
SOURCES UPDATE DATE
| db: | CNVD | id: | CNVD-2012-1342 | date: | 2012-03-16T00:00:00 |
| db: | BID | id: | 52483 | date: | 2016-07-06T14:33:00 |
SOURCES RELEASE DATE
| db: | CNVD | id: | CNVD-2012-1342 | date: | 2012-03-16T00:00:00 |
| db: | BID | id: | 52483 | date: | 2012-03-14T00:00:00 |
| db: | PACKETSTORM | id: | 110784 | date: | 2012-03-14T05:16:43 |